Back to database
Soon71High7.1VulnerabilityCVE-2026-107362No patch link observed

CVE-2026-107362 — Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Dockerfile copies all upstream…

Published Oct 8, 2026, 06:17 PM UTCIngested 5h agoSource NVD(cve-db)CVE-2026-107362

Description

Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Dockerfile copies all upstream *.php files and Malcolm only overwrites config.php and submit.php. Upstream index.php exposes a fetch API route that instructs the server to download an arbitrary URL with curl (including FOLLOWLOCATION) and, for HEAD requests, stores the fetched response body in the upload container's transfer directory and returns the transfer ID to the caller, enabling full readback of the fetched content.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
7.1

High severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

Low

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

High

Confidentiality

I

None

Integrity

A

Low

Availability