BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.WEB.AUTHZMediaWiki / Authorization
30 Sept 2026 · 4 min
MediaWiki / Authorization · 30 Sept 2026

CVE-2026-103446: Anonymous WikiLambda fragment execution

An API authorization gap let anonymous users send unsaved Abstract Wikipedia fragments to the configured evaluator.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

WikiLambda’s abstractwiki_run_fragment API accepted a caller-supplied Abstract Wikipedia fragment and sent it to the configured evaluator without checking the permission required for unsaved fragments. The related abstractwiki_fetch_section path performed that check, but the run-fragment path did not.

Technical details

An anonymous caller could submit a fragment containing a native implementation. MediaWiki forwarded the fragment to the configured WikiLambda evaluator, crossing the permission boundary intended to restrict execution of unsaved code.

The report demonstrates unauthorized code execution in the evaluator service. It does not establish code execution on the MediaWiki host or a WASM sandbox escape.

Reproduction

In a local WikiLambda setup, point the evaluator client at a loopback capture service and send an anonymous abstractwiki_run_fragment request containing a fragment with a harmless marker. The capture service receives the caller-supplied implementation. The linked PoC is limited to a loopback MediaWiki API and is intended for a local test setup.

Impact

Unauthenticated users could submit unsaved native code to a WikiLambda evaluator. The demonstrated impact is unauthorized evaluator execution; the affected evaluator is WASM-sandboxed.

References

1613 UTF-8 BYTES .WEB.AUTHZ · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.