The ReadingLists import flow accepted an attacker-controlled project URL and used the returned canonicalurl as a card link. Because the URL scheme was not checked, a malicious project response could supply a javascript: URL.
Technical details
A victim had to open a crafted Special:ReadingLists import link while signed in, then click the imported card. The attacker’s server supplied the project response and enabled cross-origin requests. The script PoC uses a loopback fixture that returns a harmless page title marker.
Reproduction
Run the PoC against a local MediaWiki instance with ReadingLists enabled. It starts a loopback fixture, prints a ReadingLists import URL, and serves a card whose canonical URL changes the local browser tab title when clicked.
Impact
Clicking the imported card executed JavaScript in the wiki origin, where it could act with the victim’s permissions. The issue required the victim to open the import link and activate the card.
References
The ReadingLists import flow accepted an attacker-controlled project URL and used the returned `canonicalurl` as a card link. Because the URL scheme was not checked, a malicious project response could supply a `javascript:` URL.
## Technical details
A victim had to open a crafted `Special:ReadingLists` import link while signed in, then click the imported card. The attacker's server supplied the project response and enabled cross-origin requests. The script PoC uses a loopback fixture that returns a harmless page title marker.
## Reproduction
Run the PoC against a local MediaWiki instance with ReadingLists enabled. It starts a loopback fixture, prints a ReadingLists import URL, and serves a card whose canonical URL changes the local browser tab title when clicked.
## Impact
Clicking the imported card executed JavaScript in the wiki origin, where it could act with the victim's permissions. The issue required the victim to open the import link and activate the card.
## References
- [CVE record](https://www.cve.org/CVERecord?id=CVE-2026-103437)
- [Public report repository](https://github.com/BomboBombone/CVE-2026-103437)
- [Phabricator report and fix tracking](https://phabricator.wikimedia.org/T435863)
- [Research index](/about/)