BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.WEB.XSSMediaWiki / XSS
25 Sept 2026 · 3 min
MediaWiki / XSS · 25 Sept 2026

CVE-2026-100380: Reflected XSS in Wikibase SetLabel errors

Special:SetLabel returned unescaped language-validation errors in its HTML response.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

Wikibase’s Special:SetLabel page could include a supplied language value in an error message before validation finished. The value was not escaped for the HTML response, so markup in an invalid language parameter appeared as a real element.

Technical details

Submitting an invalid language value containing a script element returned that element in the response before token validation completed, so the label was not saved.

The fix escapes error messages in Special:SetLabel and related term-editing pages. The affected release branches were fixed in Wikibase 1.46.1, 1.45.5, and 1.43.10.

Reproduction

  1. Confirm that WikibaseClient is installed.
  2. Submit a Special:SetLabel request with a malformed language value containing a harmless script marker.
  3. Inspect the response. Before the request can save a label, the raw script element appears in the returned HTML.

Impact

An attacker could make a victim’s browser render attacker-controlled markup in the wiki origin by getting them to open a crafted URL. The invalid language value fails validation before any label is saved.

References

1389 UTF-8 BYTES .WEB.XSS · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.