/Vulnerability Library

MediaWiki EasyTimeline - Code Injection RCE

CVE-2026-8857
Verified

Description

MediaWiki EasyTimeline (Timeline) extension versions before 1.46.0, 1.45.4, 1.44.6, and 1.43.9 contain a code injection vulnerability caused by insufficient neutralization of newlines in TextData text attributes in EasyTimeline.pl / Timeline.php. A crafted <timeline> block can inject ploticus '#proc getdata' and 'command:' directives, which execute via /bin/sh because EasyTimeline invokes ploticus without the -noshell flag. Exploitation requires the ability to submit timeline markup for rendering — low-privileged edit access, or anonymous access on wikis that allow anonymous editing and API use. This template's parse-based check needs API read access; optional username/password inputs can be supplied for private wikis that deny anonymous read.

Severity

High

CVSS Score

8.8

Exploit Probability

2%

Affected Product

easytimeline

Published Date

August 6, 2026

Template Author

pdteam

CVE-2026-8857.yaml
8.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-8857
CWE ID:
cwe-94

References

https://phabricator.wikimedia.org/T426631https://nvd.nist.gov/vuln/detail/CVE-2026-8857https://github.com/advisories/GHSA-q6xp-j96f-7vmphttps://www.mail-archive.com/wikitech-l@lists.wikimedia.org/msg97434.html

Remediation Steps

Upgrade the Timeline / EasyTimeline extension to 1.46.0, 1.45.4, 1.44.6, or 1.43.9 (or later). If an upgrade is not immediately possible, disable the EasyTimeline extension, especially when it is not executed in an isolated shellbox.