
Sanitized report and loopback-only PoC script demonstrating stored XSS via javascript: license URLs in MediaSearch QuickView (CVE-2026-103585).
Reporter: Marco Paciaroni (BomboBombone).
MediaSearch QuickView used CommonsMetadata's LicenseUrl.value directly as a link destination. CommonsMetadata copied the licensetpl_link value from an editable file description without restricting its URL scheme. An editor could store a javascript: URL; a visitor who opened that file in MediaSearch and followed the displayed license link could run script in the wiki origin.
The paired CVE-2026-103584 covers the CommonsMetadata source path.
Use a disposable file description on a local test wiki with a harmless marker:
<span class="licensetpl"><span class="licensetpl_link">javascript:alert("CVE_LICENSE_URL_XSS")</span><span class="licensetpl_short">Test license</span><span class="licensetpl_long">Local test</span></span>
Then query the local API:
python poc.py --api http://127.0.0.1:8080/w/api.php --title File:LicenseUrlProbe.png
The script checks whether the API returns the executable scheme in LicenseUrl.value. To observe the browser behavior, open the file in the local MediaSearch QuickView and follow its license link. The script only permits loopback API URLs.