
Report and PoC for CVE-2026-100381, a DOM XSS in MediaWiki UploadWizard Flickr collection and set titles, with patch verification notes and a local test harness.
Reporter: Marco Paciaroni (BomboBombone).
UploadWizard inserted Flickr collection and set titles through an API that interpreted strings as HTML. External title metadata could therefore become executable markup in the wiki page.
The CVE record identifies affected UploadWizard release branches before the fixes in 1.46.1, 1.45.5, and 1.43.10. Use the fixed extension code for the corresponding MediaWiki release branch.
Flickr importing had to be enabled, and the victim had to be allowed to use that workflow. The attacker needed control of the external collection metadata. The finding does not establish exposure in deployments where Flickr importing is disabled.
The original report records browser execution for both collection and set titles in a local instance using a controlled Flickr-compatible service. The validation did not submit an upload.
The upstream change inserts collection and set titles as text, preserving the surrounding list and link structure without parsing title metadata as HTML.
python -m pip install websocket-client
python poc.py --wiki http://127.0.0.1:4004 --username TestUser
The local test wiki must have UploadWizard's Flickr integration pointed at the loopback fixture started by the script. The PoC prompts for the password without exposing it in the process list, opens the real workflow in a local headless browser, and checks harmless collection and set markers without submitting an upload.