
PoC and patch verification notes for CVE-2026-100380, a reflected XSS in Wikibase language-validation error pages, with a script that detects unescaped HTML output.
Reporter: Marco Paciaroni (BomboBombone).
Wikibase included unescaped language-validation error text in the SetLabel page. Rejected input could be returned as executable HTML before the request reached the label-saving operation.
The CVE record identifies affected Wikibase release branches before the fixes in 1.46.1, 1.45.5, and 1.43.10. Use the fixed extension code for the corresponding MediaWiki release branch.
The archived validation records an unauthenticated request and browser execution in the wiki origin. No label save was reached. Rejecting a write does not protect an error page that renders untrusted input as HTML.
The archived case evidence records a successful local HTTP response and browser execution of a harmless marker. It separately records that no label save occurred. This public summary is based on those validation records and the associated research notes.
The upstream change HTML-escapes error messages in term-editing and related special pages before rendering them.
python poc.py https://wiki.example --entity Q1
The script posts an invalid language value containing a harmless marker and checks whether the response returns it as a raw script element. The affected path rejects the request before saving a label.