THREAT OPS › Threat News › [GHSA] GHSA-3jp5-3h47-28qf (medium) — Semantic MediaWiki has reflected XSS in Special:Ask plain table headers
[GHSA] GHSA-3jp5-3h47-28qf (medium) — Semantic MediaWiki has reflected XSS in Special:Ask plain table headers
GHSA-3jp5-3h47-28qf Severity: medium CVE: CVE-2026-77606
Semantic MediaWiki has reflected XSS in Special:Ask plain table headers
#### Failure mode
When `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. User-controlled `mainlabel` content could therefore become executable HTML.
#### Remediation
- `TableResultPrinter` now applies output-context escaping before pass
Indicators of compromise
- CVE-2026-77606cve
Original source: https://github.com/advisories/GHSA-3jp5-3h47-28qf