CVE-2025-59839 - CVE House
Back to Database
Status published High CVE-2025-59839

Star Citizen EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes

Vulnerability Description

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext. This issue has been patched via commit 4e075d3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59839

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

StarCitizenWiki

View all reports →

Affected Software

mediawiki-extensions-EmbedVideo
Vulnerable Versions:
<= 4.0.0

Timeline

Official Publish: September 25th, 2025
Last Modified: September 25th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Weaknesses (CWE)