CVE-2026-107362 — Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Dockerfile copies all upstream…
Description
Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Dockerfile copies all upstream *.php files and Malcolm only overwrites config.php and submit.php. Upstream index.php exposes a fetch API route that instructs the server to download an arbitrary URL with curl (including FOLLOWLOCATION) and, for HEAD requests, stores the fetched response body in the upload container's transfer directory and returns the transfer ID to the caller, enabling full readback of the fetched content.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:LHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
Low
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
None
Integrity
A
Low
Availability
References
Related threats
same CWE or vendorCVE-2026-107781 — Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerabili…
CVE-2026-107781 · 2h ago
CVE-2026-107394 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.
CVE-2026-107394 · 3h ago
CVE-2026-107698 — FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that fol…
CVE-2026-107698 · 5h ago
PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure
CVE-2026-61430 · 7h ago
CVE-2026-107289 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.
CVE-2026-107289 · 7h ago
CVE-2026-107288 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.
CVE-2026-107288 · 7h ago