{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awikimediacommonsmetadata/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wikimedia:commonsmetadata:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-103584"},{"id":"CVE-2026-103585"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CommonsMetadata"],"_cs_severities":["low"],"_cs_tags":["xss","web-vulnerability","wikimedia"],"_cs_type":"threat","_cs_vendors":["Wikimedia"],"content_html":"\u003cp\u003eCVE-2026-103584 is a stored XSS vulnerability identified in the CommonsMetadata component used within the Wikimedia ecosystem. The vulnerability exists because the component copies the 'licensetpl_link' value from file descriptions into the 'LicenseUrl' field of image metadata without performing necessary URL scheme validation. An attacker with low-level privileges can store a 'javascript:' URI within the metadata, which is subsequently rendered by the web interface. When a victim user interacts with this link, the embedded JavaScript executes in the context of the wiki origin. A secondary, related vulnerability, CVE-2026-103585, impacts the MediaSearch QuickView consumer path, demonstrating a broader issue with how metadata is consumed across the platform. This issue was reported by Marco Paciaroni (BomboBombone) and addressed via a patch in Gerrit.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary JavaScript execution within the context of the affected wiki origin. This could allow an attacker to hijack user sessions, perform unauthorized actions on behalf of the victim, or exfiltrate sensitive data accessible within the browser session. The vulnerability carries a low CVSS score (2.1), reflecting its reliance on user interaction and the requirement for specific metadata configuration, but it remains a security concern for platforms processing user-supplied image metadata.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVerify that the CommonsMetadata component is updated to the version containing the fix documented in Gerrit change 1346780.\u003c/li\u003e\n\u003cli\u003eAudit existing image metadata entries for suspicious URI schemes (e.g., 'javascript:') in the 'LicenseUrl' field if an automated check can be scripted against the API.\u003c/li\u003e\n\u003cli\u003eImplement strict Content Security Policy (CSP) headers to mitigate the impact of potential XSS vulnerabilities by restricting the sources from which scripts can be executed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T03:37:54Z","date_published":"2026-10-01T03:37:54Z","id":"https://feed.craftedsignal.io/briefs/2026-10-commonsmetadata-xss/","summary":"A stored cross-site scripting (XSS) vulnerability in the CommonsMetadata component, tracked as CVE-2026-103584, allows attackers to inject 'javascript:' URIs into image metadata, leading to unauthorized script execution in the wiki origin.","title":"Stored XSS in CommonsMetadata via LicenseUrl","url":"https://feed.craftedsignal.io/briefs/2026-10-commonsmetadata-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wikimedia:commonsmetadata:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}