3DAlloy allows stored XSS through attributes provided to the 3d parser tag/function
CVE-2025-59332

8.6HIGH

Key Information:

Vendor

Dolfinus

Status
Vendor
CVE Published:
15 September 2025

What is CVE-2025-59332?

3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the <3d> parser tag and the {{#3d}} parser function allow users to provide custom attributes that are then appended to the canvas HTML element that is being output by the extension. The attributes are not sanitized, which means that arbitrary JavaScript can be inserted and executed.

Affected Version(s)

3DAlloy >= 1.0, <= 1.8

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59332 : Arbitrary JavaScript Execution in 3DAlloy for MediaWiki