Impact
An authenticated user can upload a crafted archive to Malcolm’s file‑upload endpoint. The system extracts the archive without ensuring that each file’s path stays within the intended destination directory, allowing the extraction routine to write files to any location that the Malcolm service can access. This path replace or create arbitrary files, inject fabricated records into the system database, or alter application configuration files Traversal weakness and is not listed in the CISA KEV catalog.
Affected Systems
Every instance of Malcolm that exposes the archive extraction API to authenticated users is affected. The vulnerability exists in all released builds prior to the September 2026 release, so any user with valid credentials and archive‑upload privileges can exploit the flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑high level of severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild’s KEV catalog. Exploitation requires only an authenticated session and the ability to upload an archive; no additional‑level write capability of the Malcolm service, making the vulnerability both practical to exploit and potentially destructive.
OpenCVE Enrichment