Vulnerability in Wikimedia Foundation's CheckUser Tool
CVE-2025-61647

0.3LOW

Key Information:

Status
Vendor
CVE Published:
3 February 2026

What is CVE-2025-61647?

A vulnerability exists within the Wikimedia Foundation's CheckUser tool, specifically in the src/Api/Rest/Handler/UserInfoHandler.php file. This flaw could potentially allow unauthorized users to access sensitive information, undermining the tool's integrity by bypassing expected authorization mechanisms. The affected versions include specific commits, which if not addressed, may compromise user data security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CheckUser a3dc1bbcc33acbcca6831d6afaccbb1054c93a57, 0584eb2ad564648aa3ce9c555dd044dda02b55f4

References

CVSS V4

Score:
0.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.