Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser.

This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/blockConnectedTempAccountsField.Vue.



This issue affects CheckUser: from 1.46.0-rc.0 before 1.46.0.
Published: 2026-07-01
Score: 0 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Neutralization of Input during Web Page Generation (CWE‑79) located in the blockConnectedTempAccountsField component of the Wikimedia Foundation CheckUser extension. An attacker can insert JavaScript into a system message that is then stored and rendered to anyone who views that message, enabling arbitrary client‑side code execution.

Affected Systems

1.46.0, including all 1.46.0‑rc.0 release candidates up to, but not including, 1.46.0, are affected. Administrators using any pre‑1.46.0 release should review the use of the blockConnectedTempAccountsField feature and determine whether the flaw could be activated in their environment.

Risk and Exploitability

The flaw is triggered by users who have permission to block temporary accounts and supply a crafted message. Based on the description, it is inferred that an attacker must have privileged access to undertake the block operation to inject malicious payloads into stored messages. The EPSS score is below 1 % and the issue is not listed in CISA’s KEV catalog, indicating no publicly known exploits and a low probability of exploitation. The attack does not provide server‑side code execution and is limited to privileged users.

Generated by OpenCVE AI on July 21, 2026 at 14:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CheckUser to version 1.46.0 or later to remove the vulnerable component
  • If an upgrade cannot be performed immediately, disable or remove the blockConnectedTempAccountsField interface to prevent untrusted input from being stored in system messages
  • Implement output encoding or sanitization on all system messages rendered by CheckUser to neutralize injected scripts

Generated by OpenCVE AI on July 21, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 02 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Wikimedia
Wikimedia checkuser
Vendors & Products Wikimedia
Wikimedia checkuser

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/blockConnectedTempAccountsField.Vue. This issue affects CheckUser: from 1.46.0-rc.0 before 1.46.0.
Title Stored XSS through a system message when blocking a temporary account that's related to other temporary accounts
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 0, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Wikimedia Checkuser
cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-07-01T14:46:05.002Z

Reserved: 2026-06-27T13:32:41.613Z

Link: CVE-2026-58034

cve-icon Vulnrichment

Updated: 2026-07-01T14:46:00.899Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')