CVE-2026-107337: Cross-Site Request Forgery in Malcolm
The Malcolm kiosk Flask application exposes a POST /scriptcall/<script> endpoint with zero authentication and wildcard CORS (CORS(app)). An attacker can force the operator's browser to execute arbitrary management commands via CSRF, including control.py --wipe which permanently deletes all captured network traffic and forensic logs, or control.py --stop which blinds the security monitoring.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Malcolmto a version that resolves this vulnerability.Fixed in v26.08.0
Event History
Frequently Asked Questions
Does exploitation require a Malcolm account or other authenticated access?
No. The kiosk Flask application's POST /script_call/<script> endpoint has zero authentication.
What user interaction is required for an attack?
An attacker must cause the operator's browser to make the request. The vulnerability is rated UI:R, indicating required user interaction.
What operational impact could successful exploitation have?
An attacker can invoke management commands such as control.py --wipe, permanently deleting captured network traffic and forensic logs, or control.py --stop, which can blind security monitoring.