BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.WEB.XSSMediaWiki / XSS
25 Sept 2026 · 3 min
MediaWiki / XSS · 25 Sept 2026

CVE-2026-96876: Anonymous reflected XSS in CargoExport errors

CargoExport printed an invalid field alias from an exception message without HTML escaping.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

Cargo’s Special:CargoExport page printed exception messages directly into its response. The field-alias parser included a rejected alias in one such message, so an unauthenticated request could reflect an HTML element into a response the browser treated as HTML.

Technical details

The vulnerable page disabled normal MediaWiki output and printed the exception text from its catch block. Cargo rejected field aliases containing a dot or quote, but included the complete alias in the exception. A request could therefore include markup in the alias and use a trailing dot to trigger the error.

No account, CSRF token, existing Cargo table, database row, or saved page was required. The CVE record lists Cargo through 3.9.4 as affected.

Reproduction

  1. Open a Special:CargoExport URL with a nonexistent table.
  2. Set a field alias to an HTML element with a harmless script marker, followed by a dot.
  3. The invalid dot triggers the exception, which includes the unsanitized alias.
  4. The HTML response creates the script element and sets its marker.

The request did not change wiki state, and a clean alias produced no script element.

Impact

This was unauthenticated reflected cross-site scripting. A victim who opened the crafted URL ran JavaScript in the wiki origin with their session privileges.

References

1597 UTF-8 BYTES .WEB.XSS · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.