CVE-2026-107362: Server-Side Request Forgery in Malcolm
Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Dockerfile copies all upstream .php files and Malcolm only overwrites config.php and submit.php. Upstream index.php exposes a fetch API route that instructs the server to download an arbitrary URL with curl (including FOLLOWLOCATION) and, for HEAD requests, stores the fetched response body in the upload container's transfer directory and returns the transfer ID to the caller, enabling full readback of the fetched content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Malcolmto a version that resolves this vulnerability.Fixed in v26.08.0
Event History
Frequently Asked Questions
What level of access does an attacker need?
The issue is remotely reachable, but the CVSS vector indicates that the attacker needs low-level privileges. No user interaction is required.
Can an attacker retrieve content from the URL they cause the server to fetch?
Yes. For HEAD requests, the server stores the fetched response body in the upload container's transfer directory and returns a transfer ID that enables readback of that content.
Do redirects affect the destinations that can be reached?
Yes. The upstream fetch functionality uses curl with FOLLOWLOCATION enabled, so the server may follow redirects from an attacker-supplied URL.
What evidence might indicate successful exploitation?
Successful HEAD-based fetches create fetched response content in the upload container's transfer directory and produce a corresponding transfer ID returned to the caller.