THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hg8h-557g-q8pp (high) — Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes

[GHSA] GHSA-hg8h-557g-q8pp (high) — Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes

highgithub_advisoriesPublished 2026-09-18

GHSA-hg8h-557g-q8pp Severity: high CVE: CVE-2025-61682

Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes

### Summary The SemanticMediaWiki extension inserts the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext.

### Details

In `ext.smw.js`, the `data-subtab` attribute of all elements

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hg8h-557g-q8pp