VYPR

Malcolm

by Malcolm

CVEs (2)

  • CVE-2026-107362HigOct 8, 2026
    risk 0.46cvss 7.1epss —

    Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Dockerfile copies all upstream *.php files and Malcolm only overwrites config.php and submit.php. Upstream index.php exposes a fetch API route that instructs the…

  • CVE-2026-107336MedOct 8, 2026
    risk 0.42cvss 6.5epss —

    Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lowercase (for example /IDDASH2ARK/...) enters the location (the matcher fires)…