Path Traversal Vulnerability in Wikimedia Foundation MediaWiki - CSS Extension
CVE-2026-0669
7.5HIGH
What is CVE-2026-0669?
A vulnerability in the MediaWiki - CSS extension allows unauthorized access to restricted directories due to improper pathname limitation. This flaw permits attackers to traverse the file system, potentially leading to exposure of sensitive files and data. Users of MediaWiki versions 1.44, 1.43, and 1.39 are at risk, necessitating timely updates to ensure security.
Affected Version(s)
MediaWiki - CSS extension 1.44
MediaWiki - CSS extension 1.43
MediaWiki - CSS extension 1.39
