Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-103441 — Local proof-of-concept and sanitized report for CVE-2026-103441, a PHP object-injection flaw in the MediaWiki action=parse API that can reach RCE via gadget chains. | Kitploit
Tools/GitHubGitHub/bombobombone/cve-2026-103441
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPapers & ResearchPayload Development
GitHubbombobombone/cve-2026-103441

CVE-2026-103441

Local proof-of-concept and sanitized report for CVE-2026-103441, a PHP object-injection flaw in the MediaWiki action=parse API that can reach RCE via gadget chains.

View Repository
3 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-103441: Wikibase serialized entity object injection

Reporter: Marco Paciaroni (BomboBombone).

The public action=parse API accepted PHP-serialized Wikibase entities. Unrestricted object construction could reach a Smarty destructor that unlinks a caller-selected path. Available PHP gadget chains in affected Wikimedia deployments can extend this object-injection path to remote code execution.

Proof of concept

The script creates a disposable canary in a temporary directory, sends the serialized entity to a local MediaWiki API, and checks whether the PHP process removed the canary. It uses a loopback API URL only and cleans up the temporary directory.

python poc.py --api-url http://127.0.0.1:4000/api.php

Run only against an isolated local installation with Wikibase Repository and Widgets enabled.

References

  • CVE record
  • Public Phabricator report
  • Wikibase fix on Gerrit
  • Blog write-up
Download Tool