Description
URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing.

This issue affects Mediawiki - UrlShortener Extension: from * before 1.43.9, 1.44.6, 1.45.4.
Published: 2026-07-01
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Mediawiki UrlShortener Extension contains an open redirect flaw (CWE-601) that allows a user-supplied URL to bypass any host validation. An attacker can supply a malicious target URL and trick users or browsers into loading an untrusted site, enabling phishing or cross-site attacks such as Cross‑Site Flashing. This flaw exists in all releases before 1.43.9, 1.44.6 and 1.45.4.

Affected Systems

The vulnerability affects the Wikimedia Foundation’s Mediawiki UrlShortener Extension for any version released before 1.43.9, 1.44.6, or 1.45.4.

Risk and Exploitability

The CVSS score of 6.9 classifies the issue as moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker does not need authentication; the redirect is driven solely by a user‑supplied URL parameter. The likely attack vector is remote: an attacker can construct a malicious redirect link and deliver it through phishing emails, social engineering, or embedding it in a webpage to lure users onto malicious sites or induce harmful content execution.

Generated by OpenCVE AI on July 21, 2026 at 13:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mediawiki UrlShortener to version 1.43.9 or later, including the 1.44.6 and 1.45.4 releases.
  • If an upgrade cannot be performed immediately, configure the extension or site settings to allow redirects only to a curated whitelist of trusted hostnames, rejecting any other hosts.
  • Consider disabling the UrlShortener extension entirely if neither patch nor whitelist approach is feasible.

Generated by OpenCVE AI on July 21, 2026 at 13:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing. This issue affects Mediawiki - UrlShortener Extension: from * before 1.43.9, 1.44.6, 1.45.4.
Title UrlShortener defaults to ineffective validation open to third-party redirects
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-07-01T17:56:06.753Z

Reserved: 2026-07-01T03:40:44.769Z

Link: CVE-2026-58520

cve-icon Vulnrichment

Updated: 2026-07-01T17:55:57.368Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T13:45:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')