Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/bombobombone/cve-2026-103584
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPapers & Research
GitHubbombobombone/cve-2026-103584

CVE-2026-103584

Sanitized report and loopback-only PoC script for CVE-2026-103584, a javascript: URL scheme XSS in MediaWiki CommonsMetadata LicenseUrl rendering.

View Repository
2 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-103584: Unsafe license URLs in CommonsMetadata

Reporter: Marco Paciaroni (BomboBombone).

CommonsMetadata copied the licensetpl_link value from a file description into the LicenseUrl field of image metadata without restricting its URL scheme. An editor could store a javascript: URL. When an interface rendered that metadata as a link, a visitor who followed it could run script in the wiki origin.

The paired CVE-2026-103585 covers the MediaSearch QuickView consumer path.

Local reproduction

Use a disposable file description on a local test wiki with a harmless marker:

<span class="licensetpl"><span class="licensetpl_link">javascript:alert("CVE_LICENSE_URL_XSS")</span><span class="licensetpl_short">Test license</span><span class="licensetpl_long">Local test</span></span>

Then query the local API:

python poc.py --api http://127.0.0.1:8080/w/api.php --title File:LicenseUrlProbe.png

The script checks whether the API returns the executable scheme in LicenseUrl.value. To observe the browser behavior, open the file in the local MediaSearch interface and follow its license link. The script only permits loopback API URLs.

References

  • CVE record
  • Paired MediaSearch CVE-2026-103585
  • Phabricator report
  • CommonsMetadata fix on Gerrit
  • Blog write-up
Download Tool