UploadWizard inserted Flickr collection and set titles into the page with jQuery’s .append(). Flickr supplied those titles as strings, but .append() parsed a string as HTML. A title containing markup could therefore execute JavaScript when a wiki user browsed that collection in UploadWizard.
Technical details
The vulnerable collection and set paths both inserted the returned title as an HTML string. The collection title was added to a list item; each set title was added to a link. The separate thumbnail URL path was not involved.
The Flickr integration had to be enabled, and the victim had to be allowed to use the upload-from-URL workflow. The attacker needed control of a Flickr collection, but no wiki edit or administrative permission. The affected release branches were fixed in UploadWizard 1.46.1, 1.45.5, and 1.43.10.
Reproduction
- Create a Flickr collection or set with an image element and harmless error-handler marker in its title.
- Sign in to a wiki account allowed to use the Flickr import workflow.
- Open
Special:UploadWizard, choose the Flickr option, and submit the collection URL.
- The title is parsed as an image element and its handler runs. The same result occurs for a set title.
Impact
JavaScript ran in the wiki origin when an eligible user browsed the attacker-controlled collection. It could make requests available to that user’s session, subject to their permissions and browser protections.
References
UploadWizard inserted Flickr collection and set titles into the page with jQuery's `.append()`. Flickr supplied those titles as strings, but `.append()` parsed a string as HTML. A title containing markup could therefore execute JavaScript when a wiki user browsed that collection in UploadWizard.
## Technical details
The vulnerable collection and set paths both inserted the returned title as an HTML string. The collection title was added to a list item; each set title was added to a link. The separate thumbnail URL path was not involved.
The Flickr integration had to be enabled, and the victim had to be allowed to use the upload-from-URL workflow. The attacker needed control of a Flickr collection, but no wiki edit or administrative permission. The affected release branches were fixed in UploadWizard 1.46.1, 1.45.5, and 1.43.10.
## Reproduction
1. Create a Flickr collection or set with an image element and harmless error-handler marker in its title.
2. Sign in to a wiki account allowed to use the Flickr import workflow.
3. Open `Special:UploadWizard`, choose the Flickr option, and submit the collection URL.
4. The title is parsed as an image element and its handler runs. The same result occurs for a set title.
## Impact
JavaScript ran in the wiki origin when an eligible user browsed the attacker-controlled collection. It could make requests available to that user's session, subject to their permissions and browser protections.
## References
- [CVE record](https://www.cve.org/CVERecord?id=CVE-2026-100381)
- [Public report repository](https://github.com/BomboBombone/CVE-2026-100381)
- [UploadWizard fix on Gerrit](https://gerrit.wikimedia.org/r/c/mediawiki/extensions/UploadWizard/+/1345191)
- [Research index](/about/)