Home

Description

Vulnerability in Wikimedia Foundation Scribunto, Wikimedia Foundation luasandbox. This vulnerability is associated with program files includes/Engines/LuaCommon/lualib/mwInit.Lua, library.C. This issue affects Scribunto: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1; luasandbox: from * before fea2304f8f6ab30314369a612f4f5b165e68e95a.

PUBLISHED Reserved 2025-12-08 | Published 2026-02-03 | Updated 2026-02-03 | Assigner wikimedia-foundation




LOW: 1.7CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U

Product status

Default status
unaffected

* (semver) before 1.39.16, 1.43.6, 1.44.3, 1.45.1
affected

Default status
unaffected

* (semver) before fea2304f8f6ab30314369a612f4f5b165e68e95a
affected

References

phabricator.wikimedia.org/T408135

cve.org (CVE-2025-67482)

nvd.nist.gov (CVE-2025-67482)

Download JSON