PageForms’ #autoedit parser function used its redirect value directly in the href of a generated link. An editor with ordinary page-edit permission could add a javascript: URL to a page.
Technical details
The page stored the crafted link, so the issue was persistent. A visitor who viewed the page and clicked the auto-edit link ran the URL in the wiki’s origin. The PoC uses a harmless marker that adds a data attribute to the local page body.
Reproduction
On a local wiki with PageForms enabled, save the PoC wikitext on a disposable editable page and click the generated Trigger link. The marker attribute appears on the page body.
Impact
An editor could place a same-origin script link on a page. A visitor had to click it for the script to run, after which it could act with that visitor’s wiki permissions.
References
PageForms' `#autoedit` parser function used its `redirect` value directly in the `href` of a generated link. An editor with ordinary page-edit permission could add a `javascript:` URL to a page.
## Technical details
The page stored the crafted link, so the issue was persistent. A visitor who viewed the page and clicked the auto-edit link ran the URL in the wiki's origin. The PoC uses a harmless marker that adds a data attribute to the local page body.
## Reproduction
On a local wiki with PageForms enabled, save the PoC wikitext on a disposable editable page and click the generated `Trigger` link. The marker attribute appears on the page body.
## Impact
An editor could place a same-origin script link on a page. A visitor had to click it for the script to run, after which it could act with that visitor's wiki permissions.
## References
- [CVE record](https://www.cve.org/CVERecord?id=CVE-2026-103445)
- [Public report repository](https://github.com/BomboBombone/CVE-2026-103445)
- [Phabricator report](https://phabricator.wikimedia.org/T435622)
- [PageForms fix on Gerrit](https://gerrit.wikimedia.org/r/1329683)
- [Research index](/about/)