CVE-2025-61652
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-61652 is an improper input validation vulnerability in the Wikimedia Foundation's DiscussionTools MediaWiki extension. The flaw causes the Action API endpoint discussiontoolspageinfo to fail to check for authorizeRead permissions on a page, potentially exposing restricted page information to unauthorized users. It affects DiscussionTools versions prior to 1.43.4 and 1.44.1. The vulnerability was published on February 3, 2026, and carries a CVSS v4.0 base score of 2.7 (Low) (Red Hat CVE, ENISA EUVD).

Technical details

The root cause is classified as CWE-20 (Improper Input Validation), specifically a missing authorization check in the DiscussionTools Action API. The discussiontoolspageinfo API endpoint does not invoke the authorizeRead permission check before returning page metadata, allowing any network-accessible user — including unauthenticated ones — to query information about pages that may be access-restricted. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity. The vulnerability is tracked in the Wikimedia Phabricator issue tracker at T397580 (ENISA EUVD, Infinitsec).

Impact

Exploitation of this vulnerability results in a limited confidentiality impact: an unauthenticated or low-privileged attacker can retrieve metadata or information about MediaWiki pages that are intended to be restricted from public view. There is no integrity or availability impact, and the vulnerability does not enable code execution, privilege escalation, or lateral movement. The scope is limited to the DiscussionTools extension's API endpoint on affected MediaWiki installations (Red Hat CVE, ENISA EUVD).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-61652. The EPSS score is approximately 0.052% (0.000520), indicating a very low probability of exploitation in the near term. The exploit maturity is rated as "Unreported" in the CVSS v4.0 assessment, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE, Feedly).

Exploitation steps

  1. Identify target: Locate a MediaWiki instance running DiscussionTools versions prior to 1.43.4 or 1.44.1 that has restricted (non-public) pages configured.
  2. Craft API request: Send an unauthenticated HTTP GET or POST request to the MediaWiki Action API endpoint, e.g., https://[target]/api.php?action=discussiontoolspageinfo&page=[restricted_page_title]&format=json.
  3. Retrieve restricted metadata: The API responds with page information without enforcing the authorizeRead permission check, disclosing metadata about the restricted page to the unauthenticated requester.
  4. Enumerate pages: Repeat the request with different page titles to enumerate information about multiple restricted pages (Infinitsec, ENISA EUVD).

Indicators of compromise

  • Network: Unusual or repeated unauthenticated HTTP requests to /api.php with action=discussiontoolspageinfo targeting page titles that are access-restricted, originating from unexpected IP addresses.
  • Logs: MediaWiki access logs showing API calls to discussiontoolspageinfo from unauthenticated sessions or accounts without read permissions for the queried pages.
  • Logs: High volume of API requests to the discussiontoolspageinfo endpoint in a short time window, potentially indicating automated enumeration of restricted page names.

Mitigation and workarounds

Wikimedia Foundation has released patched versions of DiscussionTools: 1.43.4 and 1.44.1. MediaWiki administrators should upgrade the DiscussionTools extension to one of these versions immediately. As a temporary workaround, administrators may consider disabling the DiscussionTools extension until the patch can be applied, particularly on wikis with sensitive restricted content. Debian has also issued a security advisory (DSA-6085-1) for MediaWiki packages that includes this fix (Debian Security, ENISA EUVD).

Community reactions

The vulnerability received limited industry attention given its low CVSS score and narrow impact. Debian issued a security advisory (DSA-6085-1) covering this and related MediaWiki vulnerabilities, and Tenable published detection plugins for it. A blog post by a Wikimedia developer discussed the broader context of XSS protections in MediaWiki, tangentially referencing this class of issues (Debian Security, Tenable Plugin, Bawolff Blog).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71969NONEN/A
  • Linux Debian logoLinux Debian
  • optee-os
NoNoAug 10, 2026
CVE-2026-71968NONEN/A
  • Linux Debian logoLinux Debian
  • optee-os
NoNoAug 10, 2026
CVE-2026-71967NONEN/A
  • Linux Debian logoLinux Debian
  • optee-os
NoNoAug 10, 2026
CVE-2026-6791NONEN/A
  • Wolfi logoWolfi
  • glibc
NoYesAug 10, 2026
CVE-2026-6368NONEN/A
  • Linux Debian logoLinux Debian
  • glibc
NoNoAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management