User Details
- User Since
- Nov 18 2019, 7:30 PM (343 w, 1 d)
- Availability
- Available
- LDAP User
- Mstyles
- MediaWiki User
- MStyles (WMF) [ Global Accounts ]
May 12 2026
Posted on gerrit - https://gerrit.wikimedia.org/r/c/mediawiki/extensions/EmailAuth/+/1286455
Any objections to posting this on Gerrit?
May 5 2026
May 3 2026
Apr 28 2026
Apr 21 2026
Security issue access has been granted
Apr 16 2026
Hooks have been removed from PrivateSettings.php - https://sal.toolforge.org/log/VHnwl50B1kByGTxA1dA8
Apr 14 2026
Deployment plan (from @sbassett)
Apr 13 2026
Apr 9 2026
Email from T411394#11796980 has been sent to various mailing lists:
Apr 8 2026
Apr 7 2026
WikiLove
+(T416502, CVE-2026-22711) - Stored XSS through system messages in WikiLove
https://gerrit.wikimedia.org/r/q/Iab86209478a044504f5a6aea0d8c3d14f21c48b3
@SomeRandomDeveloper yes agreed, T414227 has been removed
Security issue access granted
Security issue access granted
Security issue access granted
Apr 3 2026
CVE/Backport Assignments
Apr 1 2026
@abi_ thank you!
Mar 23 2026
Mar 10 2026
@Pppery sorry for the markup issue, fixed now
Mar 9 2026
Security access granted
Mar 7 2026
I'll leave this open for a week for feedback/questions, but it's okay to just note the results since this is marked as low risk.
Security Review Summary - T411267 - 2026-Mar-06
Last commit reviewed: aa1f8b6
Mar 5 2026
@Nikerabbit sorry I've been out sick but will post by tomorrow
Mar 2 2026
Feb 9 2026
Security access granted
Feb 5 2026
Feb 2 2026
@abi_ Great, I'll post the review by the end of February so you have plenty of time.
Jan 28 2026
@abi_ Is this project still scheduled for deployment on Jan 31? I wanted to follow up on the timeline.
Jan 27 2026
Jan 26 2026
Jan 24 2026
Jan 23 2026
@Samwilson we will wait until this is publicly announced in the supplemental release before pushing to Gerrit.
Jan 22 2026
Jan 20 2026
Jan 9 2026
Wikibase Extension
+ (T409737, CVE-2026-22710) - Stored XSS through autocomment system messages
https://gerrit.wikimedia.org/r/q/I8505700afda8096ef4e183280494232152767004
Jan 8 2026
@Urbanecm_WMF I'm not sure what's causing the failures. I'll take a look.
@SomeRandomDeveloper thank you and I see I used the wrong tag for gerrit, apologies!
Jan 7 2026
Jan 6 2026
@Samwilson @Soda I wanted to revisit this conversation so that we can decide next steps. From the comments it does look like the CSS migration is still possible. If it's not possible, what are our other options to address this vulnerability?
CVE/Backport Assignments
Jan 5 2026
@Urbanecm following up on this task in the new year
