CVE-2025-53369: Citizen Short Description stored XSS vulnerability through wikitext
Short descriptions are not properly sanitized by the ShortDescription before being inserted as HTML using mw.util.addSubtitle
, allowing any user to insert arbitrary HTML into the DOM by editing a page.
References
- github.com/StarCitizenTools/mediawiki-extensions-ShortDescription
- github.com/StarCitizenTools/mediawiki-extensions-ShortDescription/commit/bc4fdbaeb1dff127fb6d08c0d385b64aa128c8f8
- github.com/StarCitizenTools/mediawiki-extensions-ShortDescription/security/advisories/GHSA-p85q-mww9-gwqf
- github.com/advisories/GHSA-p85q-mww9-gwqf
- nvd.nist.gov/vuln/detail/CVE-2025-53369
Code Behaviors & Features
Detect and mitigate CVE-2025-53369 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →