Impact
The vulnerability results from improper enforcement of permission checks for the unsaved-code privilege in the WikiLambda extension. An attacker can craft nested Z825 compositions that bypass the authorization check set by the ACLs, allowing execution of code without the required privileges. The primary impact is the ability to run arbitrary functions on the wiki platform, which could lead to further privilege escalation or data tampering.
Affected Systems
Affected are instances of Mediawiki with the WikiLambda extension running any version older than 1.47.0 on Linux, macOS or Windows operating systems. Users of these installations are at risk whenever the WikiLambda interface is available, as the bypass works through normal function composition mechanisms exposed by the web UI.
Risk and Exploitability
The CVSS score of 2.9 indicates a low severity score, and the EPSS is not provided, suggesting no publicly documented exploit activity. The vulnerability is not listed in the CISA KEV catalog. While the description does not explicitly state the attack vector, it is inferred that an external attacker could trigger the imbalance by submitting malicious function compositions via the web API or interface. The impact is limited to the scope of the compromised wiki instance but can allow unauthorized code execution within that system.
OpenCVE Enrichment