Hi all,
On Monday (2026-06-29) we will be issuing a security and maintenance
release to all supported branches of MediaWiki.
Due to the complexity of various patches that will be released as part of
this, they will be made public in Gerrit before the tarballs and git tags
are made.
We have therefore referenced mitigations for some high severity issues both
in the referenced tickets and below.
It is strongly recommended to apply the mitigations to your MediaWiki
installs ASAP, before the patches are released.
While Timeline/EasyTimeline[2] is *not* a MW Bundled extension, it is used
on Wikimedia wikis and is also widely used across the MediaWiki
installation ecosystem; it is therefore flagged for your attention due to
the issues found. If you do not have this extension installed, you do not
need to do anything for that mitigation.
The new releases will be:
- 1.43.9
- 1.44.6
- 1.45.4
These security issues will also be included in 1.46.0, which is due to be
released afterwards.
Security issues:
MediaWiki Core: https://phabricator.wikimedia.org/T422244 - RCE
Mitigation patch:
Making use of $wgRevokePermissions [4], the following lines can be added to
your LocalSettings.php; it will temporarily disable all importing and
therefore prevent malicious files being imported by any user:
$wgRevokePermissions['*']['importupload'] = true;
$wgRevokePermissions['*']['import'] = true;
You will want to remove these lines once you have applied the security
patches/upgraded to the latest point release versions. We recommend that
you restrict imports to trusted users.
Non-bundled extension security issues:
Timeline: https://phabricator.wikimedia.org/T426631 - RCE
A Remote Code Execution vulnerability exists in the perl script that
EasyTimeline executes to render the timelines.
If you run EasyTimeline in a similar fashion to Wikimedia Production, where
EasyTimeline’s perl scripts are executed in a remote shellbox (vm or
kubernetes), exposure is more limited.
Mitigation: Disable timeline (EasyTimeline) extension until patches are
released, especially if you do not run the execution in a remote shellbox.
Or if you have access to the security tasks, apply the patch from the task.
Timeline: https://phabricator.wikimedia.org/T427611 - Stored XSS in SVG
file output
It is possible to store an XSS in the SVG files generated by timeline.
These aren’t used by MediaWiki by default (though they may be used for RTL
timelines), but these files would still be hosted by your wiki, and could
be hot linked elsewhere.
Mitigation: Disable timeline (EasyTimeline) extension until patches are
released, especially if you do not run the execution in a remote shellbox.
Or if you have access to the security tasks, apply the patch from the task.
Appropriate CSP configuration can also help prevent XSS vectors such as
this.
—
This release will also resolve security issues in bundled extensions, along
with bug fixes included for maintenance reasons.
These security issues also affect many unsupported versions of MediaWiki.
We will make the fixes available in the respective release branches and
master in git. Tarballs will be available for the above mentioned point
releases as well.
A summary of some of the security fixes that have gone into non-bundled
MediaWiki extensions will also follow later.
As a reminder, MediaWiki 1.39 became EOL in December 2025 and MediaWiki
1.42 became EOL in June 2025.
MediaWiki 1.44 becomes EOL at the end of July 2026.
MediaWiki 1.46 is due to be released following this security release.
More information on these timelines can be viewed on the version lifecycle
page at [1].
Thank you,
Wikimedia Foundation, Product Safety and Integrity
security-help(a)wikimedia.org
[1] https://www.mediawiki.org/wiki/Version_lifecycle
[2] https://www.mediawiki.org/wiki/Extension:EasyTimeline
[3] https://www.mediawiki.org/wiki/Manual:Security#File_permissions
[4] https://www.mediawiki.org/wiki/Manual:$wgRevokePermissions
Dear MediaWiki community,
in case you are running/working with your own MediaWiki installation, please spend 15-20 minutes to fill out our MediaWiki survey. Results will be shared at the MediaWiki Users and Developers Conference Fall 2026 (November 11-13, Ljubljana, Slovenia) [1]
https://survey.knowledge.wiki/index.php/716248
The research project ECHOLOT [2] is trying to learn more about use cases of MediaWiki outside of the original projects of the Wikimedia Foundation.
We put a special focus on the GLAM sector (Galleries, Libraries Archives and Museum), but are welcoming also responses from other sectors like private or public organizations, or research and education).
Best,
Bernhard Krabina
ECHOLOT project / MediaWiki Stakeholder's group [3]
[1] https://www.mediawiki.org/wiki/MediaWiki_Users_and_Developers_Conference_Fa…
[2] https://echolot-eccch.eu
[3] https://www.mediawiki.org/wiki/MediaWiki_Stakeholders%27_Group
Save the date: The ** MediaWiki Users and Developers Conference ** (MUDCon) will take place in ** Ljubljana, Slovenia, from November 11-13 **
This event brings together developers, system administrators, researchers, and practitioners working with MediaWiki and related knowledge technologies, including Semantic MediaWiki and Wikibase.
MUDCon is a space for sharing practical experience, discussing new developments, and connecting across domains such as open knowledge, research infrastructure, and GLAM (Galleries, Libraries, Archives, and Museums).
Further details including a call for participation will be announced soon.
More information:
https://www.semantic-mediawiki.org/wiki/MediaWiki_Users_and_Developers_Conf…
We look forward to welcoming you!
MUDCon Fall 2026 is sponsored by
KM-A - https://km-a.net | MyWikis Europe - https://mywikis.eu | Professional Wiki - https://professional.wiki
The event is co-organized by the MediaWiki Stakeholder's Group, the ECHOLOT project and the Jožef Stefan Institute!
Christian Erlinger and the MUDCon organizing team.
mailto:christian.erlinger@km-a.net
Hello everyone,
We are pleased to announce the immediate availability of Semantic MediaWiki 7, the biggest SMW release in years.
Semantic MediaWiki is the OG extension that lets you store, query, and visualize structured data in your MediaWiki.
Query performance has improved, and various maintenance jobs are notably faster, in places by orders of magnitude. SMW is now easier to install by following standard MediaWiki conventions. A plain wfLoadExtension( 'SemanticMediaWiki' ) is enough, with zero extra configuration. The enableSemantics() call is no longer needed. Support for MediaWiki 1.45 and 1.46 was added, together with support for the latest PHP versions. Contributors made 24 notable enhancements and 32 bug fixes. Most SMW extensions have already been updated.
If you already run SMW, upgrading is recommended.
Full details, a list of updated extensions, and upgrade instructions are here: https://professional.wiki/en/news/semantic-mediawiki-7-released
Special thanks go to alistair3149, who led this release, and to Paladox for keeping the continuous integration infrastructure running. We are also grateful to Brian Wolff, who surfaced numerous performance issues, and to Niklas Laxström and jaideraf for testing.
Consider donating to the SMW project via https://www.semantic-mediawiki.org/wiki/Sponsorship
Best
--
Jeroen De Dauw | CEO [Professional Wiki](https://www.professional.wiki/)
Sovereign knowledge infrastructure: knowledge graphs, optional AI, open source
[NeoWiki](https://neowiki.ai/) | [AI Assistant](https://professional.wiki/en/mediawiki-ai-assistant) | [MediaWiki Hosting](https://professional.wiki/en/hosting) | [Wiki Services](https://professional.wiki/en/services)