CVE-2025-62668 Details
Description
Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Resource Leak Exposure.This issue affects Mediawiki - GrowthExperiments Extension: from master before 1.39.
A vulnerability exists in the GrowthExperiments extension of MediaWiki, specifically in the growthsetmentor API action. This issue allows users to manipulate mentorship assignments without proper authorization. The vulnerability affects MediaWiki versions through 1.39.
Users can update to the patched version of the GrowthExperiments extension, which is available in the MediaWiki Gerrit repository. Instructions for applying the update can be found in the MediaWiki documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 18, 2025CISA-ADP
Assessed Oct 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gerrit.wikimedia.org/r/q/I29a18dbbaf7e2ce2a713233dbc6880032fec3628 | wikimedia-foundation | Source CodeVendor |
| https://phabricator.wikimedia.org/T402600 | wikimedia-foundation | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | wikimedia-foundation |
Affected Products
| Product | Versions |
|---|---|
| Wikimedia Foundation Mediawiki - GrowthExperiments | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | wikimedia-foundation |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 18, 2025 | New CVE Received | wikimedia-foundation |
Volerion