CVE-2026-100382 is an OS command injection vulnerability in the Wikimedia Foundation MediaWiki ExternalData extension before version 3.7. The flaw is reachable through wikitext and permits execution of operating-system commands on the affected server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a standalone Python proof-of-concept repository for CVE-2026-100382 affecting the MediaWiki ExternalData extension before 3.7. The primary entry point, exploit.py, sends a form-encoded POST to `/api.php` with `action=parse`, causing MediaWiki to parse a `#get_program_data` parser function. It targets a configured executable data source and injects whitespace into an interpolated parameter. ExternalData expands the parameter into an administrator-defined command template and uses `explode(' ')` without preserving argument boundaries; this permits attacker-controlled additional argv tokens. When the configured program is an interpreter such as Python, injection of `-c` and Python code yields arbitrary command execution. Shell metacharacters are escaped token-by-token by MediaWiki Shell, so the demonstrated root cause is argument injection rather than direct shell-token injection. The repository contains exploit.py; intelligence and root-cause documentation in ANALYSIS.md, README.md, intel.json, and notes/; and a reproducible Docker-based lab under lab/. The lab uses MediaWiki 1.43 with ExternalData 3.6.1, exposes only 127.0.0.1, and configures a deliberately unsafe `chart` source (`python3 $options$ /srv/chart.py`) plus a harmless echo demonstration source. Bash scripts create and destroy the environment, while entrypoint.sh installs MediaWiki and appends the vulnerable extension configuration. The PoC supports target, proxy, arbitrary command, source, and parameter options; it detects the expected ExternalData 3.7 disabled-connector response. Version 3.7 mitigates the issue by disabling EDConnectorExe by default, but documentation notes that explicitly re-enabling that connector leaves the underlying interpolation/argv-splitting behavior exploitable.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An OS command injection vulnerability in the Wikimedia Foundation MediaWiki ExternalData extension affecting versions before 3.7.
A critical, remotely exploitable unauthenticated OS command-injection vulnerability in the Wikimedia MediaWiki ExternalData extension. Crafted wikitext can lead to remote code execution in versions prior to 3.7.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.