MediaWiki’s public action=parse API accepted PHP-serialized input for Wikibase entities. Wikibase deserialized the request without disabling object construction. With Widgets loaded, a crafted Smarty object graph reached a destructor that called unlink() with a request-controlled lock path.
Technical details
The demonstrated setup required Wikibase Repository and Widgets. An unauthenticated request could make the PHP process delete a file it was allowed to unlink. Available PHP gadget chains in the affected Wikimedia runtime can extend this object injection path to remote code execution. The PoC uses a fixed disposable marker path in a local test environment.
Reproduction
In a local MediaWiki instance with the affected extensions, create the marker file as a path the PHP service can remove, then run the loopback-only PoC. It submits the serialized entity through action=parse and checks whether the marker was removed.
Impact
An unauthenticated caller could reach PHP object injection in the MediaWiki process. The public PoC demonstrates deletion of a file accessible to that process; available gadget chains make remote code execution a further impact in affected deployments.
References
MediaWiki's public `action=parse` API accepted PHP-serialized input for Wikibase entities. Wikibase deserialized the request without disabling object construction. With Widgets loaded, a crafted Smarty object graph reached a destructor that called `unlink()` with a request-controlled lock path.
## Technical details
The demonstrated setup required Wikibase Repository and Widgets. An unauthenticated request could make the PHP process delete a file it was allowed to unlink. Available PHP gadget chains in the affected Wikimedia runtime can extend this object injection path to remote code execution. The PoC uses a fixed disposable marker path in a local test environment.
## Reproduction
In a local MediaWiki instance with the affected extensions, create the marker file as a path the PHP service can remove, then run the loopback-only PoC. It submits the serialized entity through `action=parse` and checks whether the marker was removed.
## Impact
An unauthenticated caller could reach PHP object injection in the MediaWiki process. The public PoC demonstrates deletion of a file accessible to that process; available gadget chains make remote code execution a further impact in affected deployments.
## References
- [CVE record](https://www.cve.org/CVERecord?id=CVE-2026-103441)
- [Public report repository](https://github.com/BomboBombone/CVE-2026-103441)
- [Phabricator report](https://phabricator.wikimedia.org/T435210)
- [Wikibase fix on Gerrit](https://gerrit.wikimedia.org/r/1346043)
- [Research index](/about/)