Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to version v26.08.0
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisagov
Cisagov malcolm |
|
| Vendors & Products |
Cisagov
Cisagov malcolm |
Thu, 08 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authentication and wildcard CORS (CORS(app)). An attacker can force the operator's browser to execute arbitrary management commands via CSRF, including control.py --wipe which permanently deletes all captured network traffic and forensic logs, or control.py --stop which blinds the security monitoring. | |
| Title | Cross-Site Request Forgery in Malcolm | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-10-08T19:06:39.091Z
Reserved: 2026-10-07T18:31:15.967Z
Link: CVE-2026-107337
No data.
Status : Awaiting Analysis
Published: 2026-10-08T18:17:20.687
Modified: 2026-10-08T21:03:43.847
Link: CVE-2026-107337
No data.
OpenCVE Enrichment
Updated: 2026-10-09T07:15:09Z
-
CWE-352
Cross-Site Request Forgery (CSRF)