
Local proof-of-concept and sanitized report for CVE-2026-103441, a PHP object-injection flaw in the MediaWiki action=parse API that can reach RCE via gadget chains.
Reporter: Marco Paciaroni (BomboBombone).
The public action=parse API accepted PHP-serialized Wikibase entities. Unrestricted object construction could reach a Smarty destructor that unlinks a caller-selected path. Available PHP gadget chains in affected Wikimedia deployments can extend this object-injection path to remote code execution.
The script creates a disposable canary in a temporary directory, sends the serialized entity to a local MediaWiki API, and checks whether the PHP process removed the canary. It uses a loopback API URL only and cleans up the temporary directory.
python poc.py --api-url http://127.0.0.1:4000/api.php
Run only against an isolated local installation with Wikibase Repository and Widgets enabled.