← Back to Feed
PoC Published for CVE-2026-58025: CVE-2026-58025
CVE-2026-58025
July 29, 2026 · GitHub · Severity: CRITICAL
Proof of Concept exploit published on GitHub: CVE-2026-58025. CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_params.
CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_params. CVSS 9.8 | CWE-502 | MediaWiki < 1.43.9, < 1.44.6, < 1.45.4, < 1.46.0
Repository: https://github.com/shinthink/CVE-2026-58025
Stars: 2
Created: 2026-07-29T18:14:30Z
Key Takeaways
- Organizations should review the published PoC and apply vendor patches immediately.
- Public PoC availability lowers the barrier for exploitation by both attackers and security tools.
- Proof of Concept exploit published on GitHub: CVE-2026-58025. CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_param. A public proof-of-concept exploit has been published for CVE-2026-58025, demonstrating exploitation methodology.