Malcolm 自助服务终端的 Flask 应用程序公开了一个无需认证且支持通配符 CORS(CORS(app))的 POST /script_call/<script> 接口。攻击者可利用该接口通过 CSRF(跨站请求伪造)攻击,强制操作人员的浏览器执行任意管理命令,例如执行 命令永久删除所有已捕获的网络流量和取证日志,或执行 命令导致安全监控功能失效。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107333 | 8.1 HIGH | Incorrect Authorization in Malcolm |
| CVE-2026-107362 | 7.1 HIGH | Server-Side Request Forgery in Malcolm |
| CVE-2026-107336 | 6.5 MEDIUM | Authentication Bypass by Spoofing in Malcolm |
| CVE-2026-107335 | 6.5 MEDIUM | Improper Handling of Highly Compressed Data in Malcolm |
| CVE-2026-107334 | 5.4 MEDIUM | Incorrect Authorization in Malcolm |
| CVE-2026-107361 | 4.2 MEDIUM | Authentication Bypass Using an Alternate Path or Channel in Malcolm |
No comments yet