CVE-2025-61649
Unknown Unknown - Not Provided

Information Disclosure Vulnerability in Wikimedia CheckUser Component

Vulnerability report for CVE-2025-61649, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-03

Last updated on: 2026-03-03

Assigner: wikimedia-foundation

Description

Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files src/Services/CheckUserUserInfoCardService.Php. This issue affects CheckUser: from 7cedd58781d261f110651b6af4f41d2d11ae7309.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-03
Last Modified
2026-03-03
Generated
2026-07-26
AI Q&A
2026-02-03
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wikimedia checkuser From 7cedd58781d261f110651b6af4f41d2d11ae7309 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the Wikimedia Foundation's CheckUser component, specifically in the program file src/Services/CheckUserUserInfoCardService.Php. The exact nature of the vulnerability is not detailed in the provided information.

Detection Guidance

I don't know

Impact Analysis

The impact of this vulnerability is not explicitly described in the provided information. Given the low CVSS base score of 1.1, it likely represents a low-severity issue with limited impact.

Compliance Impact

There is no information provided regarding the effect of this vulnerability on compliance with standards such as GDPR or HIPAA.

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-61649. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart