BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.WEB.XSSMediaWiki / XSS
01 Oct 2026 · 3 min
MediaWiki / XSS · 01 Oct 2026

CVE-2026-103584: Unsafe license URLs in CommonsMetadata

CommonsMetadata exposed editor-controlled license URLs in image metadata, which consuming interfaces could render as executable links.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

CommonsMetadata copied the licensetpl_link value from a file description into the LicenseUrl field of image metadata without restricting its URL scheme. A user who could edit a file description could therefore supply a javascript: URL.

When an interface rendered that metadata as a clickable link, a visitor who followed it could run script in the wiki’s origin. The MediaSearch QuickView path is covered by the paired CVE-2026-103585.

Reproduction

The linked PoC checks the LicenseUrl metadata from a local test wiki. To see the browser effect, use a disposable local file description with a harmless javascript:alert(...) marker, open that file in the local MediaSearch interface, and follow its license link. The PoC accepts loopback API URLs only.

Impact

An editor with file-description edit rights could store a script URL in license metadata. A visitor had to open the affected file in an interface that rendered the value as a link and follow that link for the script to run.

References

1421 UTF-8 BYTES .WEB.XSS · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.