GHSA-jfj7-249r-7j2m
TabberNeue vulnerable to Stored XSS through wikitext
Quick fix
GHSA-jfj7-249r-7j2m — starcitizentools/tabber-neue: upgrade to the fixed version with the command below.
composer require starcitizentools/tabber-neue:^3.1.1Details
### Summary Arbitrary HTML can be inserted into the DOM by inserting a payload into any allowed attribute of the `<tabber>` tag.
### Details
The `args` provided within the wikitext as attributes to the `<tabber>` tag are passed to the TabberComponentTabs class: https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/blob/3a23b703ce36cfc4128e7921841f68230be4059a/includes/Tabber.php#L76
In TabberComponentTabs, the attributes are validated before being supplied to the Tabs template. https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/blob/3a23b703ce36cfc4128e7921841f68230be4059a/includes/Components/TabberComponentTabs.php#L15-L31 However, the validation is insufficient. What `Sanitizer::validateTagAttributes` does is call `validateAttributes`, which ``` * - Discards attributes not on the given list * - Unsafe style attributes are discarded * - Invalid id attributes are re-encoded ``` However, the attribute values are expected to be escaped when inserted into HTML.
The attribute values are then inserted into HTML without being escaped: https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/blob/3a23b703ce36cfc4128e7921841f68230be4059a/includes/templates/Tabs.mustache#L1
### PoC #### XSS through attributes: 1. Go to Special:ExpandTemplates and insert the following wikitext: ``` <tabber class='test123" onmouseenter="alert(1)"'> |-|First Tab Title= First tab content goes here. </tabber> ``` 2. Press "OK" 3. Hover over the tabber

#### XSS through script tags: 1. Go to Special:ExpandTemplates and insert the following wikitext: ``` <tabber class='test123"><script>alert(2)</script>'> |-|First Tab Title= First tab content goes here. </tabber> ``` 2. Press "OK" 
### Impact Arbitrary HTML can be inserted into the DOM by any user, allowing for JavaScript to be executed.
Are you affected?
Enter the version of the package you're using.
Affected packages
3.0.0Fixed in: 3.1.1composer require starcitizentools/tabber-neue:^3.1.1References
- https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/security/advisories/GHSA-jfj7-249r-7j2m[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-53093[ADVISORY]
- https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/commit/4cdf217ef96da74a1503d1dd0bb0ed898fc2a612[WEB]
- https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/commit/62ce0fcdf32bd3cfa77f92ff6b940459a14315fa[WEB]
- https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue[PACKAGE]
- https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/blob/3a23b703ce36cfc4128e7921841f68230be4059a/includes/Components/TabberComponentTabs.php#L15-L31[WEB]
- https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/blob/3a23b703ce36cfc4128e7921841f68230be4059a/includes/Tabber.php#L76[WEB]
- https://github.com/StarCitizenTools/mediawiki-extensions-TabberNeue/blob/3a23b703ce36cfc4128e7921841f68230be4059a/includes/templates/Tabs.mustache#L1[WEB]