GHSA-9rcc-pmj8-ffhr: Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)
mediumvulnerability
security
Source: GitHub Advisory DatabaseSeptember 18, 2026
Summary
Semantic MediaWiki's Special:FacetedSearch page has a reflected XSS (cross-site scripting, where an attacker injects malicious code that runs in a user's browser) vulnerability in its `cstate` hidden input fields. An attacker can craft a malicious URL with specially crafted `cstate` parameters that bypass the checksum validation and inject JavaScript code into the page, which executes when a victim clicks the link. This is a separate instance of the same XSS flaw that was partially fixed in CVE-2025-10354.
Classification
Attack SophisticationTrivial
Affected Packages
mediawiki/semantic-media-wiki@>= 4.2.0, <= 7.2.0 (fixed: 7.2.1)
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-9rcc-pmj8-ffhr
First tracked: September 18, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 95%