Skip to main content
Vulnerability Database/CVE-2026-57440

CVE-2026-57440: MediaWiki EmbedVideo Extension XSS Flaw

CVE-2026-57440 is a cross-site scripting vulnerability in the MediaWiki EmbedVideo Extension that enables HTML and JavaScript injection through unsanitized iframe attributes. This article covers technical details, affected versions, security impact, and available mitigation strategies.

Published:

CVE-2026-57440 Overview

CVE-2026-57440 is a stored cross-site scripting (XSS) vulnerability in the EmbedVideo extension for MediaWiki. The extension adds the #ev parser function and parser tags for embedding video clips from third-party video sharing services. Prior to version 4.1.0, video URLs are passed into an iframesrc attribute without sanitization when $wgEmbedVideoRequireConsent is disabled. A malformed URL or video identifier can escape the src attribute using double quotes, enabling HTML and JavaScript injection in the rendered wiki page. The flaw is classified under [CWE-79]. Version 4.1.0 contains the patch.

Critical Impact

Any wiki editor can inject arbitrary JavaScript into pages that use the EmbedVideo parser tags, enabling session theft, account takeover, and distribution of malicious payloads to every page viewer.

Affected Products

  • EmbedVideo MediaWiki Extension versions prior to 4.1.0
  • MediaWiki instances with $wgEmbedVideoRequireConsent set to disabled
  • Wikis permitting user-submitted content that leverages the #ev parser function

Discovery Timeline

  • 2026-09-24 - CVE-2026-57440 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-57440

Vulnerability Analysis

The EmbedVideo extension renders embedded video players by constructing an HTML iframe element and inserting the user-supplied video URL or ID into the src attribute. When $wgEmbedVideoRequireConsent is disabled, the extension writes the URL directly into the attribute without applying HTML attribute encoding.

An attacker supplies a crafted URL containing a double-quote character. This terminates the src attribute string and permits injection of additional HTML attributes or event handlers. Script execution occurs in the browser context of every user who views the affected wiki page.

The exploit requires only the ability to edit a page containing an EmbedVideo tag. In many MediaWiki deployments, this is available to anonymous or low-privilege users, which aligns with the network attack vector and no privileges required characteristics of this issue.

Root Cause

The root cause is missing output encoding when generating HTML attribute values. The pre-4.1.0 implementation of EmbedHtmlFormatter concatenated untrusted input directly into HTML strings. The 4.1.0 fix rewrites EmbedHtmlFormatter to use Mustache templates, which apply contextual escaping to variables rendered with {{variable}} syntax.

Attack Vector

Exploitation requires only the ability to insert an EmbedVideo parser tag into a wiki page. The attacker supplies a URL or video ID containing a double quote followed by injected HTML such as a new attribute, an onerror handler, or a closing tag followed by a <script> block. When MediaWiki renders the page, the injected markup executes against every visitor's session.

text
// Patched template: includes/EmbedService/templates/wrapper.mustache
// Mustache applies HTML-attribute escaping to {{variable}} by default,
// preventing double-quote escape from the iframe src attribute.
+<figure class="{{class}}" data-service="{{service}}" {{#iframeConfig}}data-mw-iframeconfig="{{iframeConfig}}"{{/iframeConfig}} style="{{containerStyles}}">
+	<div class="embedvideo-wrapper" style="{{wrapperStyles}}">
+		{{{wrapperContentsHtml}}}
+	</div>{{#captionHtml}}<figcaption>{{{captionHtml}}}</figcaption>{{/captionHtml}}
+</figure>

Source: GitHub Commit for EmbedVideo

Detection Methods for CVE-2026-57440

Indicators of Compromise

  • Wiki page revisions that contain EmbedVideo tags with double-quote characters, angle brackets, or on* event-handler strings embedded in the URL or ID parameter.
  • Rendered HTML in cached pages where an iframesrc attribute terminates prematurely and is followed by inline script or additional attributes.
  • Unexpected outbound requests from reader browsers to attacker-controlled domains originating from pages that embed video content.

Detection Strategies

  • Search MediaWiki revision history and parser cache for the string pattern {{#ev: or <youtube> combined with " in the URL argument.
  • Review web server access logs for POST requests to index.php?action=edit or action=submit that contain encoded quote sequences within EmbedVideo parameters.
  • Deploy a Content Security Policy report-only header to surface unexpected inline script execution on pages containing embedded video.

Monitoring Recommendations

  • Monitor the MediaWiki recentchanges feed for edits that introduce EmbedVideo tags from anonymous or newly registered accounts.
  • Alert on browser console errors or CSP violation reports referencing EmbedVideo-rendered pages.
  • Track outbound requests from the MediaWiki host and user browsers to domains not on an approved embed provider allowlist.

How to Mitigate CVE-2026-57440

Immediate Actions Required

  • Upgrade the EmbedVideo extension to version 4.1.0 or later on every MediaWiki instance.
  • Audit existing wiki pages for EmbedVideo tags containing suspicious characters in URL or ID fields and revert malicious revisions.
  • Rotate session cookies and administrative credentials if evidence of injection is found in historical revisions.

Patch Information

The fix is published in EmbedVideo 4.1.0. The relevant commit rewrites EmbedHtmlFormatter to render through Mustache templates (wrapper.mustache and consent-container.mustache), which escape variables by default. See the GitHub Security Advisory GHSA-v65j-hff3-753c and the upstream commit for details.

Workarounds

  • Enable the consent gate by setting $wgEmbedVideoRequireConsent = true; in LocalSettings.php, which routes embed rendering through the consent container and avoids the vulnerable code path.
  • Restrict edit permissions on pages that use EmbedVideo tags to trusted users until the patch is applied.
  • Apply a strict Content Security Policy that disallows inline script execution to reduce the impact of a successful injection.
bash
# Enable consent requirement as a temporary mitigation in LocalSettings.php
echo '$wgEmbedVideoRequireConsent = true;' >> /var/www/mediawiki/LocalSettings.php

# Then upgrade the extension to the fixed release
cd /var/www/mediawiki/extensions/EmbedVideo
git fetch --tags
git checkout 4.1.0
php /var/www/mediawiki/maintenance/update.php --quick

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.