Vulnerability in Scribunto and luasandbox by Wikimedia Foundation
CVE-2025-67482

1.7LOW

Key Information:

Vendor
CVE Published:
3 February 2026

What is CVE-2025-67482?

A security vulnerability has been identified in the Scribunto extension and the luasandbox library of the Wikimedia Foundation. This vulnerability originates from issues within the LuaCommon module, specifically the mwInit.Lua file, which can lead to unauthorized code execution. Affected versions of Scribunto include any prior to 1.39.16, 1.43.6, 1.44.3, and 1.45.1, as well as luasandbox versions before the commit fea2304f8f6ab30314369a612f4f5b165e68e95a. It is critical for users and administrators to ensure their installations are updated to secure their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

luasandbox *

Scribunto * < 1.39.16, 1.43.6, 1.44.3, 1.45.1

References

CVSS V4

Score:
1.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.