{"id":"GHSA-74rh-c5rh-88vg","summary":"XWiki vulnerable to click-jacking through CSS injection in comments","details":"### Impact\n\nIt's possible using comments to inject CSS that would transform the full wiki in a link area leading to a malicious page. All versions of XWiki are impacted by this kind of attack. \n\n### Patches\n\nThe problem has been patched not by preventing injecting CSS in comments, which is currently a feature of XWiki, but by requiring confirmation from users when driving them to untrusted domains after clicking on a link, thus preventing any click-jacking attack. \nThis security measure has been put in place in XWiki 17.9.0, 17.4.6, 16.10.13.\n\n### Workarounds\n\nThere's no out-of-the-box workaround, but it should be possible to partly reuse [the javascript code provided for the security measure](https://github.com/xwiki/xwiki-platform/blob/xwiki-platform-17.9.0/xwiki-platform-core/xwiki-platform-web/xwiki-platform-web-war/src/main/webapp/resources/uicomponents/link/link-protection.js) in a JSX object inside the wiki, to request the same kind of confirmation. \n\n### References\n  * JIRA ticket: https://jira.xwiki.org/browse/XWIKI-23433\n  * Documentation of the new security measure: https://www.xwiki.org/xwiki/bin/view/ReleaseNotes/Data/XWiki/17.9.0RC1/Entry006/\n  * Commit for the security fix: https://github.com/xwiki/xwiki-platform/commit/29cb81f3a5387cf822d7e7534bdd63903275f86b\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Email us at [Security Mailing List](mailto:security@xwiki.org)\n\n### Attribution\n\nThanks Tomas Keech (Sentrium Security Ltd) for reporting this vulnerability.","aliases":["CVE-2026-26000"],"modified":"2026-02-12T22:26:23.787527Z","published":"2026-02-12T15:54:19Z","database_specific":{"github_reviewed_at":"2026-02-12T15:54:19Z","nvd_published_at":"2026-02-12T21:16:02Z","cwe_ids":["CWE-1021"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-74rh-c5rh-88vg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26000"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/pull/4645"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/29cb81f3a5387cf822d7e7534bdd63903275f86b"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/7b5a4f8c34d9b1da3d966e17f7dbccabac448e75"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-17.4.6"},{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-23433"},{"type":"WEB","url":"https://www.xwiki.org/xwiki/bin/view/ReleaseNotes/Data/XWiki/17.9.0RC1/Entry006"}],"affected":[{"package":{"name":"org.xwiki.platform:xwiki-platform-web","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"17.5.0"},{"fixed":"17.9.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-74rh-c5rh-88vg/GHSA-74rh-c5rh-88vg.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-web","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"17.0.0-rc-1"},{"fixed":"17.4.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-74rh-c5rh-88vg/GHSA-74rh-c5rh-88vg.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-web","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"16.10.13"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-74rh-c5rh-88vg/GHSA-74rh-c5rh-88vg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}