THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7xv3-gf2g-498h (medium) — Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS

[GHSA] GHSA-7xv3-gf2g-498h (medium) — Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS

medgithub_advisoriesPublished 2026-09-18

GHSA-7xv3-gf2g-498h Severity: medium CVE: CVE-2026-77607

Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS

#### Failure mode

`sep` was inserted verbatim into the HTML that joins a table cell's values. This made it possible to inject HTML through the separator value. The same unsanitised table HTML is produced both for the standard `Special:Ask` render and for its ra

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7xv3-gf2g-498h