BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.WEB.XSSMediaWiki / XSS
25 Sept 2026 · 3 min
MediaWiki / XSS · 25 Sept 2026

CVE-2026-100381: DOM XSS in UploadWizard Flickr titles

UploadWizard treated Flickr collection and set titles as HTML instead of text.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

UploadWizard inserted Flickr collection and set titles into the page with jQuery’s .append(). Flickr supplied those titles as strings, but .append() parsed a string as HTML. A title containing markup could therefore execute JavaScript when a wiki user browsed that collection in UploadWizard.

Technical details

The vulnerable collection and set paths both inserted the returned title as an HTML string. The collection title was added to a list item; each set title was added to a link. The separate thumbnail URL path was not involved.

The Flickr integration had to be enabled, and the victim had to be allowed to use the upload-from-URL workflow. The attacker needed control of a Flickr collection, but no wiki edit or administrative permission. The affected release branches were fixed in UploadWizard 1.46.1, 1.45.5, and 1.43.10.

Reproduction

  1. Create a Flickr collection or set with an image element and harmless error-handler marker in its title.
  2. Sign in to a wiki account allowed to use the Flickr import workflow.
  3. Open Special:UploadWizard, choose the Flickr option, and submit the collection URL.
  4. The title is parsed as an image element and its handler runs. The same result occurs for a set title.

Impact

JavaScript ran in the wiki origin when an eligible user browsed the attacker-controlled collection. It could make requests available to that user’s session, subject to their permissions and browser protections.

References

1752 UTF-8 BYTES .WEB.XSS · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.