
Sanitized report and loopback-only PoC for CVE-2026-102971, a MediaWiki REST revision response leaking hidden revision author user IDs.
Reporter: Marco Paciaroni (BomboBombone).
MediaWiki's RESTBase-compatible revision response could include the numeric user ID of an author whose name had been hidden. The response still set user_text to null and marked the author as hidden, but the exposed ID could be mapped to an account through the public user lookup API.
An unauthenticated caller could correlate a deliberately hidden revision author with the author's account. The disclosure requires a revision whose author field is hidden and a wiki exposing the core REST revision route.
The script creates a disposable local page, hides the author of its new revision, compares the standard REST response with RESTBase compatibility enabled, checks that the local public user lookup resolves the ID, and cleans up the page and revision state.
Run it only against an isolated MediaWiki test instance on loopback. It refuses non-loopback hosts and requires an explicit confirmation flag. It prompts for the test account password instead of accepting it on the command line.
python poc.py --base http://127.0.0.1:8080 --username LocalAdmin --confirm-local-test
The account needs permission to edit a disposable page and hide its revision author (suppressrevision).