Cross-Site Scripting Vulnerability in MediaWiki EmbedVideo Extension
CVE-2026-55690
7.5HIGH
What is CVE-2026-55690?
The EmbedVideo Extension for MediaWiki allows users to embed video clips from various sharing services. A vulnerability exists in versions prior to 4.1.0, where the EmbedServiceFactory interpolates a user-controlled service name into exception messages. This can lead to an attacker injecting malicious HTML or JavaScript through error outputs, which executes in the context of the wiki for users who view the page. The issue has been addressed in version 4.1.0 with appropriate security measures.
Affected Version(s)
mediawiki-extensions-EmbedVideo < 4.1.0
