Intel

AIKIDO-2026-777865

mediawiki/semantic-media-wiki is vulnerable to Missing Authorization

Missing AuthorizationGHSA-rjqv-6r83-pg8v Published 2 days ago

73

High Risk

This Affects:

PHPmediawiki/semantic-media-wiki
7.3.0 - 7.3.0
Fixed in 7.3.1
Are you affected? Scan for Free

TL;DR

The smwtask API module's authorization check in Semantic MediaWiki only validates a CSRF token and does not verify the caller is authorized for the page named in the request. An unauthenticated caller can still queue background jobs and force store updates for a page they cannot edit, an incomplete fix for a prior advisory that stopped at token enforcement without a per page authorization check. The patch adds a per page authorization check in the task dispatch path before the task runs.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

mediawiki/semantic-media-wiki is vulnerable to Missing Authorization in versions 7.3.0 - 7.3.0.

How to fix this

Upgrade the mediawiki/semantic-media-wiki library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform