Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters) — GHSA-59XW-QV23-J3RC
GitHub · GitHub · GHSA-59XW-QV23-J3RC
ID
GHSA-59XW-QV23-J3RC
GHSA-59XW-QV23-J3RC
Date
Source
GitHub
GitHub
Vendor
GitHub
GitHub
Threat
medium
medium
CVSS
6.1
6.1
Summary
#### Failure mode The `value` parameter was reflected back into rendered output and error messaging paths without enough output-context encoding. #### Remediation - The form value is escaped before it is placed back into the input field. - Derived error messages are also escaped before being rendered into HTML. #### Maintenance note Do not treat error text as trusted just because it originated from validation.…
Timeline
- Published by source
- 2026-09-18
Risk context
- Reported severity or threat level: medium.
- Reported CVSS score: 6.1 out of 10.
- Review exposure for the affected product or family: composer: mediawiki/semantic-media-wiki.
Product
composer: mediawiki/semantic-media-wiki
What to do
General, cautious steps (verify details in the official source):
- Review exposure and plan remediation based on risk and environment.
- Identify affected product versions in your inventory and verify whether you are impacted.
- Apply vendor patches/updates or recommended mitigations as soon as available.
- Read the official advisory for exact affected versions and remediation steps.
Official advisory
Evidence and provenance
- Canonical advisory ID
- GHSA-59XW-QV23-J3RC
- Source
- GitHub
- Vendor
- GitHub
- Published by source
- 2026-09-18
- Last source activity
- 2026-09-18
- Additional identifiers
- CVE-2026-77608
- Curated by
- hlukh.ch
Related advisories and connections
These advisories are connected by shared CVE, product, vendor, source, or time signals.