External risk intelligence

Mediawiki ExternalData Extension OS Command Injection

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-100382

The ExternalData extension is used within MediaWiki to fetch and process data from external sources. While MediaWiki instances are often public-facing, this specific extension is an optional component and not a default or core service that is invariably exposed to the internet, making public reachability dependent on specific site configurations.

OS Command Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns an OS Command Injection vulnerability found in a Mediawiki extension used for handling external data. While the technology is widely used, the specific extension is optional, meaning exposure depends on individual configurations. The main concern is confirming relevance and assessing potential exposure within your environment.

  • Allows unauthorized command execution.
  • Relevant if using external data features.
  • Confirm use and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could potentially exploit this vulnerability if the ExternalData extension is enabled in Mediawiki. This extension handles data from external sources, and an attacker might be able to send specially crafted input that manipulates underlying operating system commands. Successful exploitation could allow an attacker to execute arbitrary commands on the server.

  • Extension is enabled and accessible.
  • Specially crafted input is sent to the extension.
  • Arbitrary command execution on the server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary operating system commands on the server when the ExternalData extension is configured to process untrusted input. This could impact the confidentiality, integrity, and availability of the affected system.

  • Server command execution.
  • Processing untrusted external data.
  • Compromise of system integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Wikimedia Foundation's ExternalData extension for MediaWiki is susceptible to OS Command Injection. This impacts instances before version 3.7. Ownership of this issue likely resides with the platform or application teams managing the MediaWiki deployment, with input from security teams to assess exposure. The first practical step involves identifying all MediaWiki instances utilizing the ExternalData extension, determining their reachability and criticality, and then engaging the accountable owner to plan remediation.

  • Platform/application teams own the issue.
  • Verify ExternalData extension usage and reachability.
  • Plan remediation based on asset criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the MediaWiki ExternalData extension?

The ExternalData extension is an optional add-on for the MediaWiki platform, which powers sites like Wikipedia. It enables administrators to fetch, parse, and display data from external web sources or databases directly within wiki pages. Because it acts as an interface for pulling outside information, it requires specialized handling of data inputs to ensure the server remains secure.

What is the vulnerability in CVE-2026-100382?

This vulnerability is classified as OS Command Injection (CWE-78). It occurs when the software incorrectly handles special characters in input, allowing that input to be interpreted as system-level commands. In the context of this CVE, it means the extension might inadvertently pass malicious, user-provided data directly to the underlying operating system for execution.

How does an attacker trigger this command injection?

An attacker triggers the bug by sending specially crafted input to the extension that the server then processes. The vulnerability requires the ExternalData extension to be actively enabled and configured to handle untrusted or externally sourced data. If the extension is not enabled, or if it is configured to only process trusted, static data sources, the specific conditions for this injection path are not met.

Is my MediaWiki site vulnerable according to Halo Surface Signal?

Halo Surface Signal indicates that risk depends on your specific site configuration. While MediaWiki is often public-facing, this extension is not a core component and may not be exposed to the internet on every deployment. You should prioritize checking instances where this extension is both enabled and accessible to outside traffic, as those are the primary paths for potential reachability.

What steps should I take if I use this extension?

First, perform an inventory to identify all MediaWiki instances where the ExternalData extension is currently installed and active. Determine which of these instances are reachable from the network and verify their current version. If you are running a version earlier than 3.7, coordinate with your platform or application teams to update the extension and mitigate the command injection risk.

References