Impact
The vulnerable web interface includes a portion of the request that can be triggered by any network user. An attacker can craft a link containing malicious JavaScript; when an end‑user opens the link inside the Malcolm application, the script executes in the context of the application and can redirect the user's browser to an arbitrary external site. Successful exploitation allows the attacker to act with the compromised user's session rights, potentially leading to further exploitation of the system.
Affected Systems
Instances of the Malcolm platform that release are affected. Versions released before September ; upgrading to the September 2026 or later release resolves the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. The EPSS score of < 1% and the fact that it is not listed in CISA KEV suggest that widespread exploitation is unlikely. The attack vector is straightforward for an unauthenticated attacker, who only needs to send a crafted link that a user will subsequently open.
OpenCVE Enrichment