MediaSearch QuickView used the LicenseUrl.value from CommonsMetadata directly as a link destination. Because CommonsMetadata accepted the licensetpl_link value from a file description without checking its scheme, an editor could store a javascript: URL.
A visitor who opened the file in Special:MediaSearch and followed the displayed license link could run script in the wiki’s origin. The metadata source is covered by the paired CVE-2026-103584.
Reproduction
The linked PoC checks the metadata condition against a local test wiki. For the browser demonstration, use a disposable local file description containing a harmless javascript:alert(...) marker, open the file in local MediaSearch QuickView, and click its license link. The PoC accepts loopback API URLs only.
Impact
An editor with file-description edit rights could create the stored script URL. A visitor had to open the affected file in MediaSearch and follow the license link for the script to run.
References
MediaSearch QuickView used the `LicenseUrl.value` from CommonsMetadata directly as a link destination. Because CommonsMetadata accepted the `licensetpl_link` value from a file description without checking its scheme, an editor could store a `javascript:` URL.
A visitor who opened the file in `Special:MediaSearch` and followed the displayed license link could run script in the wiki's origin. The metadata source is covered by the paired [CVE-2026-103584](/posts/cve-2026-103584/).
## Reproduction
The linked PoC checks the metadata condition against a local test wiki. For the browser demonstration, use a disposable local file description containing a harmless `javascript:alert(...)` marker, open the file in local MediaSearch QuickView, and click its license link. The PoC accepts loopback API URLs only.
## Impact
An editor with file-description edit rights could create the stored script URL. A visitor had to open the affected file in MediaSearch and follow the license link for the script to run.
## References
- [CVE record](https://www.cve.org/CVERecord?id=CVE-2026-103585)
- [Public report repository](https://github.com/BomboBombone/CVE-2026-103585)
- [Paired CommonsMetadata CVE-2026-103584](/posts/cve-2026-103584/)
- [Phabricator report](https://phabricator.wikimedia.org/T435999)
- [MediaSearch fix on Gerrit](https://gerrit.wikimedia.org/r/1346778)
- [Research index](/about/)