PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39837 Mediawiki CVE debrief

CVE-2026-39837 is a basic XSS vulnerability in Mediawiki - Cargo Extension before 3.8.7 due to improper neutralization of Script-Related HTML tags. This allows for Stored XSS attacks. The issue affects Mediawiki - Cargo Extension versions before 3.8.7. Users of affected versions should apply patches or updates to prevent XSS attacks. The vulnerability has a CVSS score of 6.3 and is considered Medium priority.

Vendor
Mediawiki
Product
Cargo
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-07
Original CVE updated
2026-07-24
Advisory published
2026-04-07
Advisory updated
2026-07-24

Who should care

Users of Mediawiki - Cargo Extension before version 3.8.7 should apply patches to prevent XSS attacks. This includes operators, administrators, and security teams responsible for maintaining and securing Mediawiki - Cargo Extension deployments. Additionally, vulnerability management teams should review and prioritize patching of affected systems.

Technical summary

The CVE-2026-39837 vulnerability is caused by improper neutralization of Script-Related HTML tags in the Mediawiki - Cargo Extension. This allows for Stored XSS attacks. The issue affects Mediawiki - Cargo Extension versions before 3.8.7. The vulnerability has a CVSS score of 6.3 and is considered Medium priority. Defenders should review official advisories and apply patches or updates to prevent exploitation.

Defensive priority

Medium priority due to CVSS score of 6.3 and potential for Stored XSS attacks.

Recommended defensive actions

  • Apply the patch from https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1237979
  • Review and follow vendor advisory at https://phabricator.wikimedia.org/T416402
  • Update Mediawiki - Cargo Extension to version 3.8.7 or later
  • Monitor for suspicious activity related to Stored XSS attacks
  • Perform inventory checks for affected versions
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

Evidence from NVD and CVE.org confirms the vulnerability exists in Mediawiki - Cargo Extension before 3.8.7. The vulnerability is caused by improper neutralization of Script-Related HTML tags, allowing for Stored XSS attacks. Defenders should verify the existence of affected product deployments and review official advisories for mitigation guidance. Additional evidence and context are limited, and further verification is required to determine the full scope of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-39837 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-39837

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-39837 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39837

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1237979

    c4f26cc8-17ff-4c99-b5e2-38fc1793eacc - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://phabricator.wikimedia.org/T416402

    c4f26cc8-17ff-4c99-b5e2-38fc1793eacc - Exploit, Issue Tracking, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.