Impact
Maler header directly into a redirect response without verifying that the value originates from the same domain. This insecure practice enables an authenticated attacker to craft a file‑upload request that, after the upload completes, forces the victim’s browser to navigate to an attacker‑controlled external site, representing an open redirect flaw (CWE‑601). The vulnerability does not provide direct code execution or privilege escalation; its primary effect is to move the user’s session to a potentially malicious destination.
Affected Systems
All Malcolm installations in use by CISA that were deployed prior to the release of the September 2026 update are vulnerable. The September 2026 version removes the unsafe redirect logic, so any older installation remains exposed.
Risk and Exploitability
The CVSS score of 5.1 classifies the flaw as moderate. The EPSS score of < 1 % indicates a very low likelihood that the flaw will be exploited in the wild, and the vulnerability is not yet listed in CISA’s KEV catalog. Exploitation requires an authenticated user capable of sending a request with a contrived Referer header to the upload endpoint; once triggered, it redirects the victim’s browser to the attacker’s specified URL.
OpenCVE Enrichment