CommonsMetadata copied the licensetpl_link value from a file description into the LicenseUrl field of image metadata without restricting its URL scheme. A user who could edit a file description could therefore supply a javascript: URL.
When an interface rendered that metadata as a clickable link, a visitor who followed it could run script in the wiki’s origin. The MediaSearch QuickView path is covered by the paired CVE-2026-103585.
Reproduction
The linked PoC checks the LicenseUrl metadata from a local test wiki. To see the browser effect, use a disposable local file description with a harmless javascript:alert(...) marker, open that file in the local MediaSearch interface, and follow its license link. The PoC accepts loopback API URLs only.
Impact
An editor with file-description edit rights could store a script URL in license metadata. A visitor had to open the affected file in an interface that rendered the value as a link and follow that link for the script to run.
References
CommonsMetadata copied the `licensetpl_link` value from a file description into the `LicenseUrl` field of image metadata without restricting its URL scheme. A user who could edit a file description could therefore supply a `javascript:` URL.
When an interface rendered that metadata as a clickable link, a visitor who followed it could run script in the wiki's origin. The MediaSearch QuickView path is covered by the paired [CVE-2026-103585](/posts/cve-2026-103585/).
## Reproduction
The linked PoC checks the `LicenseUrl` metadata from a local test wiki. To see the browser effect, use a disposable local file description with a harmless `javascript:alert(...)` marker, open that file in the local MediaSearch interface, and follow its license link. The PoC accepts loopback API URLs only.
## Impact
An editor with file-description edit rights could store a script URL in license metadata. A visitor had to open the affected file in an interface that rendered the value as a link and follow that link for the script to run.
## References
- [CVE record](https://www.cve.org/CVERecord?id=CVE-2026-103584)
- [Public report repository](https://github.com/BomboBombone/CVE-2026-103584)
- [Paired MediaSearch CVE-2026-103585](/posts/cve-2026-103585/)
- [Phabricator report](https://phabricator.wikimedia.org/T435999)
- [CommonsMetadata fix on Gerrit](https://gerrit.wikimedia.org/r/1346780)
- [Research index](/about/)