yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2026-39841
Component Overview
Vulnerability Overview
Name
CVE-2026-39841
Source
NVD (
link
)
Debian (
link
)
Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.
CWEs
CWE-80
CWE-79
Published Date
Apr 7, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1237973
Patch
https://phabricator.wikimedia.org/T416389
Exploit
Analysis
#
Affected Component
Analysis
cargo
Exploitable
Vulnerability Ratings
#
6.3
CVSSv4
6.1
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
cargo
yocto
master
1.96.0
Not Affected
cargo
yocto
scarthgap
1.75.0
Not Affected