CVE-2025-67482
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-67482 is a sandbox bypass vulnerability in Wikimedia Foundation's Scribunto extension and luasandbox library, affecting MediaWiki installations. The flaw is associated with the files includes/Engines/LuaCommon/lualib/mwInit.Lua and library.C, and allows Lua scripts to execute outside their intended security constraints. Affected versions include Scribunto before 1.39.16, 1.43.6, 1.44.3, and 1.45.1, and luasandbox before commit fea2304f8f6ab30314369a612f4f5b165e68e95a. It carries a CVSS v4.0 base score of 1.7 (Low), though the broader impact on wiki content integrity may be more significant in practice (Red Hat CVE, EUVD).

Technical details

The vulnerability stems from insufficient sandboxing enforcement in the Lua execution environment used by the Scribunto MediaWiki extension. Specifically, weaknesses in mwInit.Lua and the C-level library.C allow crafted Lua scripts to escape the sandbox and execute code outside the intended security boundaries (CWE classification not formally assigned, but consistent with sandbox escape/improper isolation). The attack vector is network-based, requires no privileges or user interaction, but does require specific attack conditions to be present (AT:P in CVSS 4.0 terms), making exploitation non-trivial. The Wikimedia Foundation's Phabricator task T408135 tracks the underlying issue (Red Hat CVE).

Impact

Successful exploitation could allow an attacker to execute arbitrary Lua code outside the sandbox within a MediaWiki wiki environment, potentially compromising content integrity and enabling privilege escalation within the wiki platform. The availability impact is rated Low, with no direct confidentiality or integrity impact at the system level per the CVSS scoring, though wiki content and configurations could be manipulated. Lateral movement beyond the wiki environment is unlikely given the constrained execution context, but abuse of wiki administrative functions post-exploitation is a concern (Red Hat CVE, EUVD).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-67482. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. Exploit maturity is classified as "Unreported" per CVSS 4.0 metadata, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The requirement for specific attack conditions (AT:P) further reduces the practical exploitability of this flaw (Red Hat CVE).

Mitigation and workarounds

Wikimedia Foundation has released patched versions addressing this vulnerability: Scribunto 1.39.16, 1.43.6, 1.44.3, and 1.45.1, and luasandbox at or after commit fea2304f8f6ab30314369a612f4f5b165e68e95a. Debian has also issued security advisories (DSA-6085-1 and DLA-4428-1) for MediaWiki packages incorporating these fixes. Administrators running affected MediaWiki installations should upgrade the Scribunto extension and luasandbox library to the patched versions as soon as possible (Debian Security Announce, Debian LTS Announce, Red Hat CVE).

Community reactions

The vulnerability received standard coverage from Linux distribution security channels, with Debian issuing advisories for both stable (DSA-6085-1) and LTS (DLA-4428-1) releases. Tenable published Nessus detection plugins (IDs 278543 and 279440) for the affected packages. No notable researcher commentary or significant social media discussion has been identified beyond routine vulnerability tracking (Debian Security Announce, Tenable Nessus).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63343CRITICAL9.9
  • Linux Debian logoLinux Debian
  • incus
NoYesAug 21, 2026
CVE-2026-63125CRITICAL9.9
  • Linux Debian logoLinux Debian
  • incus
NoYesAug 21, 2026
CVE-2026-62941CRITICAL9.9
  • Linux Debian logoLinux Debian
  • incus
NoYesAug 21, 2026
CVE-2026-62940CRITICAL9.9
  • Linux Debian logoLinux Debian
  • incus
NoYesAug 21, 2026
CVE-2026-62867CRITICAL9.9
  • Linux Debian logoLinux Debian
  • incus
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management