GHSA-7xv3-gf2g-498h

Suggest an improvement
Source
https://github.com/advisories/GHSA-7xv3-gf2g-498h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-7xv3-gf2g-498h/GHSA-7xv3-gf2g-498h.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-7xv3-gf2g-498h
Aliases
Published
2026-09-18T16:50:01Z
Modified
2026-09-18T17:00:06Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS
Details

Failure mode

sep was inserted verbatim into the HTML that joins a table cell's values. This made it possible to inject HTML through the separator value. The same unsanitised table HTML is produced both for the standard Special:Ask render and for its raw request output (request_type=raw), so the injection was reachable without authentication.

Remediation

  • In all non-wiki output modes (HTML, raw request, file), sep is escaped unless it is a safe <br> variant.
  • This preserves legitimate line-break separators while blocking markup injection.

Maintenance note

If the table renderer ever gains richer separator semantics, keep the whitelist explicit. Do not expand the allowed HTML surface casually.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-18T16:50:01Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / mediawiki/semantic-media-wiki

Package

Name
mediawiki/semantic-media-wiki
Purl
pkg:composer/mediawiki/semantic-media-wiki

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.2.0

Affected versions

1.*
1.9beta1
1.9-RC1
1.9
1.9.0.1
1.9.0.2
1.9.1
1.9.1.1
1.9.2
2.*
2.0-RC1
2.0-RC2
2.0-RC3
2.0
2.1.0-RC1
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0-RC1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0-RC1
2.3.0
2.3.1
2.4.0-RC1
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0-rc.1
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.5.7
2.5.8
3.*
3.0.0-rc.1
3.0.0-rc.2
3.0.0
3.0.1
3.0.2
3.1.0-rc.1
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.2.0-rc.1
3.2.0-rc.2
3.2.0
3.2.1
3.2.2
3.2.3
4.*
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
5.*
5.0.0
5.0.1
5.0.2
5.1.0
6.*
6.0.0
6.0.1
7.*
7.0.0
7.1.0

Database specific

last_known_affected_version_range
"<= 7.1.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-7xv3-gf2g-498h/GHSA-7xv3-gf2g-498h.json"