CVE-2026-96876

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ryx@PadhiyarRushi

    MediaWiki Cargo export prints the exception raw. Field alias becomes script in the wiki origin! CVE-2026-96876: Cargo through 3.9.4, CargoExport emits the exception message with no HTML escape. Anonymous path, no saved page required. Victim opens the crafted export error and the script runs with their permissions. Fix HTML-escapes the message. Reporter: Marco Paciaroni. PoC 29 Sep. https://github.com/BomboBombone/CVE-2026-96876 #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #XSS #BugBounty

    20063156
    943 followersView on X

Explore more