Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107337— Cross-Site Request Forgery in Malcolm

Quick assessment

Affected
CISA Malcolm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Malcolm 自助服务终端的 Flask 应用程序公开了一个无需认证且支持通配符 CORS(CORS(app))的 POST /script_call/<script> 接口。攻击者可利用该接口通过 CSRF(跨站请求伪造)攻击,强制操作人员的浏览器执行任意管理命令,例如执行 命令永久删除所有已捕获的网络流量和取证日志,或执行 命令导致安全监控功能失效。

CVSS 7.1 · High

Affected Version Matrix 2

VendorProduct Version RangeStatus
CISA Malcolm ≤ 26.07.1 affected
26.08.0 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107337

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cross-Site Request Forgery in Malcolm
Source: CVE Program / CVE List V5
Vulnerability Description
The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authentication and wildcard CORS (CORS(app)). An attacker can force the operator's browser to execute arbitrary management commands via CSRF, including control.py --wipe which permanently deletes all captured network traffic and forensic logs, or control.py --stop which blinds the security monitoring.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨站请求伪造(CSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
CISA Malcolm 0 ~ 26.07.1 -

II. Public POCs for CVE-2026-107337

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107337

请登录查看更多情报信息。

Other References for CVE-2026-107337 (2)

Same Patch Batch · CISA · 2026-10-08 · 7 CVEs total

CVE-2026-107333 8.1 HIGH Incorrect Authorization in Malcolm
CVE-2026-107362 7.1 HIGH Server-Side Request Forgery in Malcolm
CVE-2026-107336 6.5 MEDIUM Authentication Bypass by Spoofing in Malcolm
CVE-2026-107335 6.5 MEDIUM Improper Handling of Highly Compressed Data in Malcolm
CVE-2026-107334 5.4 MEDIUM Incorrect Authorization in Malcolm
CVE-2026-107361 4.2 MEDIUM Authentication Bypass Using an Alternate Path or Channel in Malcolm

IV. Related Vulnerabilities

V. Comments for CVE-2026-107337

No comments yet


Leave a comment