Vulnerability GHSA-c29q-5xm7-5p62

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 19, 2026 at 09:14 PM UTC
StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text
3.0.0 - 4.0.0
3.0.0 - 4.0.0

Summary

StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text

Details

Summary

When passing an unknown service name to embedvideo, an error message is rendered containing the invalid service name. The service name is not sanitized and can contain HTML.

Details

There is a hardcoded list of allowed services in a switch statement inside EmbedServiceFactory#newFromName here. When the service name is not known, an exception is thrown with the service name injected into the message via sprintf here. This message is not sanitized and is marked as isHtml here. Similarly with {{evl: here.

PoC

// Must be on a page, not on ExpandTemplates
{{#ev:<img src=x onerror=alert(document.domain)>|dQw4w9WgXcQ}}
{{#evl:id=dummy|service=<img src=x onerror=alert(document.domain)>}}

Impact

Stored XSS that allows arbitrary Javascript/HTML insertion on any page that a user can edit. It requires no interaction and executes in the wiki origin for every visitor to the page.

Timeline

Published
3 months ago
June 19, 2026 at 09:14 PM UTC
Fixed (4.1.0)
3 months ago
June 19, 2026 at 06:27 PM UTC
Last Modified
18 days ago
September 10, 2026 at 03:50 AM UTC