CVE-2025-59839 | Star Citizen EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes
Exp
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext. This issue has been patched via commit 4e075d3.
Conclusion & alert: CVE-2025-59839 is rated Exploit Available (51.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.03%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2025-59839
Exploit prediction scoring system (EPSS) score for CVE-2025-59839
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
GHSA-4j5h-mvj3-m48v · Severity: high · Ecosystem: composer — Star Citizen EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes
Affected software / configurations for CVE-2025-59839