Remote Code Execution and Denial of Service Vulnerabilities in MediaWiki Extension by Miraheze
CVE-2025-53371

9.1CRITICAL

Key Information:

Vendor

Miraheze

Vendor
CVE Published:
10 July 2025

What is CVE-2025-53371?

The DiscordNotifications extension for MediaWiki is vulnerable due to its ability to send requests to arbitrary URLs defined by the user. This functionality can lead to Denial of Service (DoS) attacks by requesting large files, overwhelming the server. Additionally, if there are internal APIs that lack proper protection, attackers could exploit this vulnerability using HTTP POST requests, potentially leading to Remote Code Execution (RCE). The issue has been addressed in commit 1f20d850cbcce5b15951c7c6127b87b927a5415e.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

DiscordNotifications < 1f20d850cbcce5b15951c7c6127b87b927a5415e

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.