The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authentication and wildcard CORS (CORS(app)). An attacker can force the operator's browser to execute arbitrary management commands via CSRF, including control.py --wipe which permanently deletes all captured network traffic and forensic logs, or control.py --stop which blinds the security monitoring.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update to version v26.08.0
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authentication and wildcard CORS (CORS(app)). An attacker can force the operator's browser to execute arbitrary management commands via CSRF, including control.py --wipe which permanently deletes all captured network traffic and forensic logs, or control.py --stop which blinds the security monitoring. | |
| Title | Cross-Site Request Forgery in Malcolm | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-10-08T19:06:39.091Z
Reserved: 2026-10-07T18:31:15.967Z
Link: CVE-2026-107337
No data.
Status : Awaiting Analysis
Published: 2026-10-08T18:17:20.687
Modified: 2026-10-08T21:03:43.847
Link: CVE-2026-107337
No data.
OpenCVE Enrichment
Updated: 2026-10-08T18:30:07Z
Weaknesses