mediumCVSS 6.1Vulnerability

CVE-2026-77616

## Reflected XSS via a forged cursor pagination token #### Failure mode `Special:Ask` accepts a `cursor` query parameter for keyset pagination (added in 7.0.0). The token is decoded by `CursorEncoder`, which is an **unsigned** base64url-encoded JSON blob, so its contents are fully attacker-controlled. When the cursor's sort anchor does not match the request's `sort=` / `order=`, `QueryCreator::applyCursorIfRequested()` builds an error message by interpolating the attacker-controlled `sort_prop` / `sort_order` values into a raw string via `Query::addErrors()`. Unlike SMW's message-key errors, this raw string bypasses the message layer's sanitisation (`ProcessingErrorMsgHandler::normalizeAndDecodeMessages()` passes a non-key, non-encoded string through unchanged). `ErrorWidget::queryError()` then assembles the errors and passes them to `Html::errorBox()`, whose first argument is emitted as raw HTML. The result is a reflected cross-site scripting vulnerability: a crafted `cursor` token containing markup in `sort_prop` (or `sort_order`) executes script in the victim's browser on the wiki origin. No authentication or special permission is required. The payload is delivered via a crafted link, e.g. `Special:Ask?q=...&p[cursor]=<forged token>` where the token decodes to `{"v":1,"sort_prop":"<script>...</script>"}`. Confirmed executing in a browser; the responses carry no Content-Security-Policy, so inline script is not blocked. #### Remediation - Output-encode the attacker-controlled `sort_prop` / `sort_order` values before they are interpolated into the error text in `QueryCreator`, so no raw user input enters the error stream. - Defense in depth: the `format=debug` output path that reflected the same error text was hardened separately in GHSA-q5fm-9mx6-44f4. #### Maintenance note Query error strings are rendered as raw HTML by `ErrorWidget::queryError()` via `Html::errorBox()`. Any error added through `Query::addErrors()` that embeds user-controlled text must be

Properties

ghsa_id
GHSA-cx86-7xwp-w9wf
severity
medium
summary
Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cursor pagination token
cvss_score
6.1
cve_id
CVE-2026-77616
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
signal_observed_at
2026-09-18T17:46:44+00:00
is_ghsa_only
false
ghsa_published
2026-09-18T16:58:50Z
source_url
https://github.com/advisories/GHSA-cx86-7xwp-w9wf
ghsa_updated
2026-09-18T16:58:52Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/mediawiki/semantic-media-wiki

AFFECTS (1)

[Software]composer/mediawiki/semantic-media-wiki

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77616 (CVSS 6.1) — Ninja Signal Threat Intelligence | Ninja Signal