Wikimedia Foundation MediaWiki BlueSky Skin Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Wikimedia Foundation MediaWiki BlueSky skin, affecting versions prior to 1.39. This issue arises from improper escaping of system message content, which is inserted as raw HTML, allowing malicious scripts to be executed.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Reproduction

To reproduce this vulnerability, edit the MediaWiki:Sidebar page and add a script tag containing JavaScript, such as an alert command. After saving the changes, visit any page where the sidebar is displayed. The injected script will execute, demonstrating the cross-site scripting vulnerability.

Remediation

Users can update to MediaWiki BlueSky skin version 1.39 or later, where this vulnerability has been addressed.

Added: Oct 18, 2025, 4:17 AM
Updated: Oct 18, 2025, 4:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.6
remediation
0.0
relevance
0.7
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.