Cybersecurity and Infrastructure Security Agency Malcolm是Cybersecurity and Infrastructure Security Agency组织的一款网络流量与日志分析平台。 Cybersecurity and Infrastructure Security Agency Malcolm 26.07.0之前版本存在路径遍历漏洞,该漏洞源于safe-extract.py创建目录条目时缺乏路径遍历保护,可能导致上传包含../序列或绝对路径的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55676 | 8.8 HIGH | Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component |
| CVE-2026-63177 | 7.1 HIGH | Malcolm Vulnerable to Authorization Bypass via URI Normalization Differential in Nginx Lua |
| CVE-2026-63133 | 6.5 MEDIUM | Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS) |
No comments yet