shinthink/CVE-2026-58025
🔴SkipNew discovery — enrichment pending(New discovery — enrichment pending)
CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_params. CVSS 9.8 | CWE-502 | MediaWiki < 1.43.9, < 1.44.6, < 1.45.4, < 1.46.0
Why this repo matters
- •Demonstrates a critical deserialization RCE vulnerability in MediaWiki.
- •Affects multiple recent versions of MediaWiki, posing a widespread risk.
- •Provides a proof-of-concept for security researchers and pentesters.
Key Metrics
- Stars: 5
- Forks: 1
- Open Issues: 0
- Stars (7d delta): 0
- Stars (30d delta): 0
Scores & Metadata
- Trend Velocity Score: 0.00
- Opportunity Score: 10.00
- Confidence Score: 90.00
- Language: Python
- Topics:
- First Seen: 2 months ago
Star History
5 stars+1 over 9 snapshots8/9/2026 – 9/4/2026