Cargo’s Special:CargoExport page printed exception messages directly into its response. The field-alias parser included a rejected alias in one such message, so an unauthenticated request could reflect an HTML element into a response the browser treated as HTML.
Technical details
The vulnerable page disabled normal MediaWiki output and printed the exception text from its catch block. Cargo rejected field aliases containing a dot or quote, but included the complete alias in the exception. A request could therefore include markup in the alias and use a trailing dot to trigger the error.
No account, CSRF token, existing Cargo table, database row, or saved page was required. The CVE record lists Cargo through 3.9.4 as affected.
Reproduction
- Open a
Special:CargoExport URL with a nonexistent table.
- Set a field alias to an HTML element with a harmless script marker, followed by a dot.
- The invalid dot triggers the exception, which includes the unsanitized alias.
- The HTML response creates the script element and sets its marker.
The request did not change wiki state, and a clean alias produced no script element.
Impact
This was unauthenticated reflected cross-site scripting. A victim who opened the crafted URL ran JavaScript in the wiki origin with their session privileges.
References
Cargo's `Special:CargoExport` page printed exception messages directly into its response. The field-alias parser included a rejected alias in one such message, so an unauthenticated request could reflect an HTML element into a response the browser treated as HTML.
## Technical details
The vulnerable page disabled normal MediaWiki output and printed the exception text from its catch block. Cargo rejected field aliases containing a dot or quote, but included the complete alias in the exception. A request could therefore include markup in the alias and use a trailing dot to trigger the error.
No account, CSRF token, existing Cargo table, database row, or saved page was required. The CVE record lists Cargo through 3.9.4 as affected.
## Reproduction
1. Open a `Special:CargoExport` URL with a nonexistent table.
2. Set a field alias to an HTML element with a harmless script marker, followed by a dot.
3. The invalid dot triggers the exception, which includes the unsanitized alias.
4. The HTML response creates the script element and sets its marker.
The request did not change wiki state, and a clean alias produced no script element.
## Impact
This was unauthenticated reflected cross-site scripting. A victim who opened the crafted URL ran JavaScript in the wiki origin with their session privileges.
## References
- [CVE record](https://www.cve.org/CVERecord?id=CVE-2026-96876)
- [Public report repository](https://github.com/BomboBombone/CVE-2026-96876)
- [Cargo fix on Gerrit](https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1328630)
- [Research index](/about/)