
Sanitized report and loopback-only PoC script for CVE-2026-103584, a javascript: URL scheme XSS in MediaWiki CommonsMetadata LicenseUrl rendering.
Reporter: Marco Paciaroni (BomboBombone).
CommonsMetadata copied the licensetpl_link value from a file description into the LicenseUrl field of image metadata without restricting its URL scheme. An editor could store a javascript: URL. When an interface rendered that metadata as a link, a visitor who followed it could run script in the wiki origin.
The paired CVE-2026-103585 covers the MediaSearch QuickView consumer path.
Use a disposable file description on a local test wiki with a harmless marker:
<span class="licensetpl"><span class="licensetpl_link">javascript:alert("CVE_LICENSE_URL_XSS")</span><span class="licensetpl_short">Test license</span><span class="licensetpl_long">Local test</span></span>
Then query the local API:
python poc.py --api http://127.0.0.1:8080/w/api.php --title File:LicenseUrlProbe.png
The script checks whether the API returns the executable scheme in LicenseUrl.value. To observe the browser behavior, open the file in the local MediaSearch interface and follow its license link. The script only permits loopback API URLs.