GHSA-3jp5-3h47-28qf: XSS

Published Sep 18, 2026
·
Updated

Failure mode

When headers=plain, table header text was emitted into <th> via a raw HTML path. User-controlled mainlabel content could therefore become executable HTML.

Remediation

- TableResultPrinter now applies output-context escaping before passing plain headers to the table renderer. - The fix is limited to the HTML/plain-header branch so safe rendering modes are unaffected.

Why this is the right layer

The header value is not a structural token; it is display data. Sanitizing it at the sink is correct because the renderer owns the final HTML emission.

Affected Software

1 affected componentFixes available
composer/mediawiki/semantic-media-wiki<=7.1.0
7.2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/mediawiki/semantic-media-wiki to a version that resolves this vulnerability.

    Fixed in 7.2.0

Event History

Sep 18, 2026
Advisory Published
via GitHub·04:40 PM
Data Sourced
via GitHub·04:40 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Exposure is limited to HTML table output using headers=plain. Safe rendering modes are unaffected by this fix.

2

What must an attacker be able to control?

An attacker needs to supply user-controlled mainlabel content that is rendered as a plain table header. Exploitation also requires a user to view the resulting rendered HTML.

3

How can I identify potentially affected output?

Review Semantic MediaWiki table output that uses headers=plain and determine whether its mainlabel value can contain untrusted content. Those outputs are the relevant candidates for this issue.

4

What changes in the remediation?

The TableResultPrinter applies output-context escaping to plain headers before they reach the table renderer. This prevents mainlabel display data from being emitted through the raw HTML header path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203