CVE-2026-107337

CVE-2026-107337 published: The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authentication and wildcard CORS (CORS(app)). An attacker can force the operator's browser to execute arbitrary management commands via CSRF, including control.py --...

View full NVD advisory → ← Back to CVE watch