Reflected Cross-Site Scripting in MediaWiki Cargo Extension
The Cargo extension for MediaWiki is vulnerable to reflected XSS via unescaped field-alias text in export error messages, allowing unauthenticated attackers to execute arbitrary scripts in the wiki's origin.
CVE search metadata
CVE search record: CVE-2026-96876. EPSS: 0.26%. KEV: no. Product: Cargo (<= 3.9.4). Brief: Reflected Cross-Site Scripting in MediaWiki Cargo Extension. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cargo-xss/
The MediaWiki Cargo extension, versions up to 3.9.4, contains a security vulnerability (CVE-2026-96876) resulting from improper sanitization of exception messages. Specifically, error messages generated during export operations fail to HTML-escape untrusted input derived from field-alias text. An unauthenticated attacker can craft a malicious HTTP request that forces the application to return an error page containing executable markup. If a victim visits the crafted URL, the injected script executes within the context of the wiki origin, potentially allowing unauthorized actions or data access using the victim's session privileges. The vulnerability was reported by Marco Paciaroni and fixed by the upstream maintainers via a patch that mandates HTML-escaping for all exception messages before rendering them in export responses.
Impact
Successful exploitation allows for reflected cross-site scripting (XSS) in the context of the affected wiki. An attacker can use this to execute arbitrary JavaScript in the victim's browser session, which could lead to session hijacking, defacement of the wiki content, or unauthorized interactions with the wiki platform. As this is an unauthenticated vector, any public-facing MediaWiki instance utilizing the Cargo extension (version 3.9.4 or earlier) is potentially at risk of exploitation by external actors.
Recommendation
- Upgrade the MediaWiki Cargo extension to a version that includes the fix for CVE-2026-96876.
- Apply the vendor-provided patch available at the Gerrit tracking task: https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1328630.
- Audit existing MediaWiki configurations to identify if the Cargo extension is enabled and confirm the current version in use.
Immediate actions
Upgrade MediaWiki Cargo extension to a patched version.
Mitigations
Deploy patch from Gerrit (https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1328630).
CVE-2026-96876