
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67478 is a vulnerability in the Wikimedia Foundation's CheckUser MediaWiki extension, specifically associated with the includes/Mail/UserMailer.php file. It affects CheckUser versions from 1.39.0 before 1.39.14, 1.43.0 before 1.43.4, and 1.44.0 before 1.44.1. The vulnerability was published on February 3, 2026, and carries a CVSS v3.1 base score of 8.8 (High), requiring user interaction but no authentication (Red Hat CVE, Feedly). A technical write-up describing the issue as "wrong e-mail address composition for usernames with a comma and umlauts" has been published (infinitsec).
The vulnerability resides in includes/Mail/UserMailer.php within the CheckUser extension and relates to improper construction of email addresses for usernames containing special characters such as commas and umlauts. This malformed email address composition can be exploited by an unauthenticated network attacker when a user interacts with the affected functionality, suggesting a potential email header injection or address spoofing scenario. The root cause appears to be insufficient sanitization or encoding of special characters in username-derived email fields (infinitsec, Phabricator). The associated Wikimedia task is tracked at Phabricator T385403 (Phabricator).
Successful exploitation of CVE-2025-67478 can result in high impact to confidentiality, integrity, and availability of affected CheckUser installations, as reflected in the CVSS v3.1 scoring. An unauthenticated attacker leveraging this vulnerability via network access — with user interaction as a precondition — could potentially manipulate email communications, expose sensitive user data handled by the CheckUser extension, or disrupt the extension's functionality (Red Hat CVE, Feedly). Given that CheckUser is used by wiki administrators to investigate user activity, compromise of this component could expose sensitive investigative data about users.
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.063%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Organizations should upgrade the CheckUser MediaWiki extension to the patched versions: 1.39.14 or later for the 1.39.x branch, 1.43.4 or later for the 1.43.x branch, or 1.44.1 or later for the 1.44.x branch (Red Hat CVE, Phabricator). Debian has also issued security advisories (DSA-6085-1 and DLA-4428-1) for affected MediaWiki packages (Debian Security, Debian LTS). If immediate patching is not feasible, consider temporarily restricting access to CheckUser functionality as a workaround.
Debian issued security advisories DSA-6085-1 and DLA-4428-1 addressing this and related MediaWiki vulnerabilities (Debian Security, Debian LTS). Tenable published Nessus detection plugins (IDs 278533 and 279440) for the vulnerability. A researcher at infinitsec published a technical description characterizing the issue as incorrect email address composition for usernames with commas and umlauts (infinitsec). No significant social media discussion or major media coverage has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."