Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS
Moderate severity
GitHub Reviewed
Published
Jul 18, 2026
in
SemanticMediaWiki/SemanticMediaWiki
•
Updated Sep 18, 2026
Description
Published to the GitHub Advisory Database
Sep 18, 2026
Reviewed
Sep 18, 2026
Last updated
Sep 18, 2026
Failure mode
sepwas inserted verbatim into the HTML that joins a table cell's values. This made it possible to inject HTML through the separator value. The same unsanitised table HTML is produced both for the standardSpecial:Askrender and for its raw request output (request_type=raw), so the injection was reachable without authentication.Remediation
sepis escaped unless it is a safe<br>variant.Maintenance note
If the table renderer ever gains richer separator semantics, keep the whitelist explicit. Do not expand the allowed HTML surface casually.
References