BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.WEB.XSSMediaWiki / XSS
01 Oct 2026 · 3 min
MediaWiki / XSS · 01 Oct 2026

CVE-2026-103585: Stored XSS in MediaSearch QuickView

MediaSearch QuickView used an editor-controlled license URL as a link without restricting executable URL schemes.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

MediaSearch QuickView used the LicenseUrl.value from CommonsMetadata directly as a link destination. Because CommonsMetadata accepted the licensetpl_link value from a file description without checking its scheme, an editor could store a javascript: URL.

A visitor who opened the file in Special:MediaSearch and followed the displayed license link could run script in the wiki’s origin. The metadata source is covered by the paired CVE-2026-103584.

Reproduction

The linked PoC checks the metadata condition against a local test wiki. For the browser demonstration, use a disposable local file description containing a harmless javascript:alert(...) marker, open the file in local MediaSearch QuickView, and click its license link. The PoC accepts loopback API URLs only.

Impact

An editor with file-description edit rights could create the stored script URL. A visitor had to open the affected file in MediaSearch and follow the license link for the script to run.

References

1401 UTF-8 BYTES .WEB.XSS · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.