CVE-2025-61682: Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes
### Summary The SemanticMediaWiki extension inserts the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. ### Details In `ext.smw.js`, the `data-subtab` attribute of all elements with the `smw-subtab` class is parsed as JSON and appended to the `innerHTML` of the element: https://github.com/SemanticMediaWiki/SemanticMediaWiki/blob/62f1fa765b626e21d88999b97a3e8029db9fd385/res/smw/ext.smw.js#L37-L42 However, most data attributes (except for reserved ones) like `data-subtab` can be used in wikitext. Therefore, it is possible to insert arbitrary HTML and JS through wikitext. The decoded (`"` will turn to `"`, but it will be decoded when it is retrieved through `.dataset`) value of the `data-subtab` attribute in the payload is `"<img src='' onerror=alert(1)>"`. This is valid JSON and returns a string with `<img src='' onerror=alert(1)>` when being decoded. ### PoC 1. Create a page with the following contents: ```html {{#tag:div| |class=smw-subtab |data-subtab=""<img src='' onerror=alert(1)>"" }} ``` 2. Visit the page <img width="991" height="465" alt="image" src="https://github.com/user-attachments/assets/5d28d852-72d6-41dc-a59a-faac1610015f" /> <img width="497" height="69" alt="image" src="https://github.com/user-attachments/assets/02309390-0b40-46d9-b690-de8cd25dba59" /> ### Impact Arbitrary HTML can be inserted into the DOM by any user with the `edit` right, allowing for JavaScript to be executed.
Recommended action
Recommended action
Upgrade affected packages to a patched version: mediawiki/semantic-media-wiki 7.0.0.
Technical details
- Vendor
- Not specified
- Product
- mediawiki/semantic-media-wiki
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source