Skip to main content
Vulnerability Database/CVE-2026-103050

CVE-2026-103050: MediaWiki MassMessage Extension XSS Flaw

CVE-2026-103050 is a stored cross-site scripting vulnerability in MediaWiki MassMessage extension that enables attackers to inject malicious scripts. This article covers the technical details, affected versions, and remediation.

Published:

CVE-2026-103050 Overview

CVE-2026-103050 is a stored cross-site scripting (XSS) vulnerability [CWE-79] in the Wikimedia Foundation MediaWiki MassMessage extension. The flaw stems from improper neutralization of user-supplied input during web page generation. Attackers can inject persistent script payloads that execute in the browsers of users who view affected pages. The vulnerability affects MassMessage extension versions before 1.46.1, 1.45.5, and 1.43.10.

Critical Impact

Successful exploitation enables persistent script execution in the context of victim sessions, allowing session hijacking, account takeover, and unauthorized actions against MediaWiki installations that rely on the MassMessage extension.

Affected Products

  • Wikimedia MediaWiki MassMessage extension versions before 1.46.1
  • Wikimedia MediaWiki MassMessage extension versions before 1.45.5
  • Wikimedia MediaWiki MassMessage extension versions before 1.43.10

Discovery Timeline

  • 2026-09-30 - CVE-2026-103050 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-103050

Vulnerability Analysis

The MassMessage extension automates delivery of messages to multiple MediaWiki talk pages. The vulnerability arises when user-controlled content is rendered into generated pages without proper output encoding. An attacker with the ability to submit content processed by MassMessage can embed malicious HTML or JavaScript that persists in stored data. When another user loads the affected page, the browser executes the payload in the context of the MediaWiki origin.

Stored XSS in a widely deployed wiki extension carries elevated risk because privileged users, including administrators, may trigger the payload during routine review. Payloads can perform actions using the victim's authenticated session, exfiltrate CSRF tokens, or pivot to modify wiki content and permissions.

Root Cause

The root cause is improper neutralization of input during web page generation [CWE-79]. The extension does not adequately sanitize or encode specific user-supplied fields before including them in HTML output. Fix commits are tracked in the upstream Wikimedia Gerrit Change and referenced task Wikimedia Phabricator Task.

Attack Vector

An authenticated user submits crafted input to a MassMessage workflow that stores the payload. When any user renders the page containing the injected content, the payload executes in the victim's browser. No memory corruption or server-side code execution occurs; impact is limited to the client and any actions reachable through the victim's session.

Refer to the upstream patch for exact injection points and the neutralization applied. No public proof-of-concept exploit is currently referenced in the advisory data.

Detection Methods for CVE-2026-103050

Indicators of Compromise

  • Unexpected <script> tags, on* event handlers, or javascript: URIs present in MassMessage-generated content or associated wiki pages.
  • Outbound requests from user browsers to unknown domains immediately after loading MassMessage pages, indicating potential token or cookie exfiltration.
  • Administrative account changes, permission modifications, or content edits that correlate with rendering of MassMessage pages.

Detection Strategies

  • Review MediaWiki page revision history for MassMessage-related edits containing HTML tags, event handlers, or encoded script payloads.
  • Correlate web server access logs with wiki audit logs to identify anomalous session activity following MassMessage page views.
  • Deploy a Content Security Policy (CSP) in report-only mode to surface inline script execution attempts on wiki pages.

Monitoring Recommendations

  • Alert on the introduction of raw HTML or JavaScript patterns in MassMessage inputs and rendered output.
  • Monitor privileged MediaWiki accounts for anomalous API calls originating from browser sessions rather than typical administrative workflows.
  • Track version metadata across MediaWiki installations to confirm that the MassMessage extension is running a patched build.

How to Mitigate CVE-2026-103050

Immediate Actions Required

  • Upgrade the MassMessage extension to 1.46.1, 1.45.5, or 1.43.10 depending on the deployed MediaWiki release branch.
  • Audit MassMessage-generated pages for existing injected payloads and revert affected revisions.
  • Rotate session tokens and review privileged account activity for indicators of misuse during the exposure window.

Patch Information

The Wikimedia Foundation resolved the issue in MassMessage extension versions 1.46.1, 1.45.5, and 1.43.10. Patch details are available in the Wikimedia Gerrit Change with tracking through the Wikimedia Phabricator Task. Apply the version corresponding to the MediaWiki core release in use and restart web workers to load the updated extension code.

Workarounds

  • Restrict permissions to submit or trigger MassMessage operations to a minimal set of trusted users until patching is complete.
  • Enforce a strict Content Security Policy that disallows inline scripts and untrusted script sources on wiki origins.
  • Temporarily disable the MassMessage extension in LocalSettings.php if patching cannot be scheduled immediately.
bash
# Configuration example: disable MassMessage in LocalSettings.php until patched
# wfLoadExtension( 'MassMessage' );

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.