BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.WEB.XSSMediaWiki / XSS
30 Sept 2026 · 4 min
MediaWiki / XSS · 30 Sept 2026

CVE-2026-103437: XSS through imported ReadingLists links

ReadingLists used imported canonical URLs as card links without validating their URL scheme.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

The ReadingLists import flow accepted an attacker-controlled project URL and used the returned canonicalurl as a card link. Because the URL scheme was not checked, a malicious project response could supply a javascript: URL.

Technical details

A victim had to open a crafted Special:ReadingLists import link while signed in, then click the imported card. The attacker’s server supplied the project response and enabled cross-origin requests. The script PoC uses a loopback fixture that returns a harmless page title marker.

Reproduction

Run the PoC against a local MediaWiki instance with ReadingLists enabled. It starts a loopback fixture, prints a ReadingLists import URL, and serves a card whose canonical URL changes the local browser tab title when clicked.

Impact

Clicking the imported card executed JavaScript in the wiki origin, where it could act with the victim’s permissions. The issue required the victim to open the import link and activate the card.

References

1253 UTF-8 BYTES .WEB.XSS · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.