CVE-2026-58520 Details
Description
URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing. This issue affects Mediawiki - UrlShortener Extension: from * before 1.43.9, 1.44.6, 1.45.4.
A vulnerability allowing open redirection to untrusted sites has been identified in the Wikimedia Foundation's MediaWiki UrlShortener Extension. This issue affects versions prior to 1.43.9, 1.44.6, and 1.45.4. The vulnerability arises because the extension's default validation settings allow third-party redirects, which can be exploited for Cross-Site Flashing.
Users can update to the latest version of the MediaWiki UrlShortener Extension to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gerrit.wikimedia.org/r/q/I7a59cc4c351b5aa47ed46f7a14a1105fd1ecc5b5 | wikimedia-foundation | Issue Tracking |
| https://phabricator.wikimedia.org/T418431 | wikimedia-foundation | Issue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | wikimedia-foundation |
Affected Products
| Product | Versions |
|---|---|
| mediawiki mediawiki | >= 1.43.0, < 1.43.9 >= 1.44.0, < 1.44.6 >= 1.45.0, < 1.45.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | wikimedia-foundation |