CVE-2026-39841: Stored XSS through list fields on Cargo's page values and Special:CargoTables
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39841?
The severity of CVE-2026-39841 is classified as medium due to its potential for exploitation through stored cross-site scripting (XSS).
How do I fix CVE-2026-39841?
To fix CVE-2026-39841, upgrade the MediaWiki Cargo Extension to version 3.8.7 or later where this vulnerability is resolved.
What impact does CVE-2026-39841 have on users?
CVE-2026-39841 can lead to unauthorized execution of scripts in the context of the user's session, which may compromise user accounts and data.
Which versions of MediaWiki are affected by CVE-2026-39841?
CVE-2026-39841 affects all versions of the MediaWiki Cargo Extension prior to version 3.8.7.
Is CVE-2026-39841 a remote attack vector?
Yes, CVE-2026-39841 can be exploited remotely by an attacker who can store malicious scripts through the Cargo extension.