<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:mediawiki:cargo:*:*:*:*:*:mediawiki:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amediawikicargomediawiki/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 15:35:57 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amediawikicargomediawiki/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Reflected Cross-Site Scripting in MediaWiki Cargo Extension</title><link>https://feed.craftedsignal.io/briefs/2026-09-cargo-xss/</link><pubDate>Tue, 29 Sep 2026 15:35:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cargo-xss/</guid><description>The Cargo extension for MediaWiki is vulnerable to reflected XSS via unescaped field-alias text in export error messages, allowing unauthenticated attackers to execute arbitrary scripts in the wiki's origin.</description><content:encoded><![CDATA[<p>The MediaWiki Cargo extension, versions up to 3.9.4, contains a security vulnerability (CVE-2026-96876) resulting from improper sanitization of exception messages. Specifically, error messages generated during export operations fail to HTML-escape untrusted input derived from field-alias text. An unauthenticated attacker can craft a malicious HTTP request that forces the application to return an error page containing executable markup. If a victim visits the crafted URL, the injected script executes within the context of the wiki origin, potentially allowing unauthorized actions or data access using the victim's session privileges. The vulnerability was reported by Marco Paciaroni and fixed by the upstream maintainers via a patch that mandates HTML-escaping for all exception messages before rendering them in export responses.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for reflected cross-site scripting (XSS) in the context of the affected wiki. An attacker can use this to execute arbitrary JavaScript in the victim's browser session, which could lead to session hijacking, defacement of the wiki content, or unauthorized interactions with the wiki platform. As this is an unauthenticated vector, any public-facing MediaWiki instance utilizing the Cargo extension (version 3.9.4 or earlier) is potentially at risk of exploitation by external actors.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the MediaWiki Cargo extension to a version that includes the fix for CVE-2026-96876.</li>
<li>Apply the vendor-provided patch available at the Gerrit tracking task: <a href="https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1328630">https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1328630</a>.</li>
<li>Audit existing MediaWiki configurations to identify if the Cargo extension is enabled and confirm the current version in use.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>