
MediaWiki Cargo export prints the exception raw. Field alias becomes script in the wiki origin! CVE-2026-96876: Cargo through 3.9.4, CargoExport emits the exception message with no HTML escape. Anonymous path, no saved page required. Victim opens the crafted export error and the script runs with their permissions. Fix HTML-escapes the message. Reporter: Marco Paciaroni. PoC 29 Sep. https://github.com/BomboBombone/CVE-2026-96876 #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #XSS #BugBounty
