CVE-2026-0669
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wikimedia Foundation MediaWiki - CSS extension allows Path Traversal.This issue affects MediaWiki - CSS extension: 1.44, 1.43, 1.39.
CWE
- CWE-22 — CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected
- Wikimedia Foundation / MediaWiki - CSS extension — v=1.44 [affected]; v=1.43 [affected]; v=1.39 [affected]
CVSS
- (none)
References
- https://phabricator.wikimedia.org/T401526
- https://gerrit.wikimedia.org/r/q/Ia15bf3f2e5a341868568492a736ac3dbf706c22e
Source
cvelistV5-main/cves/2026/0xxx/CVE-2026-0669.json