Metrics
Affected Vendors & Products
No advisories yet.
Solution
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.
Workaround
No workaround given by the vendor.
Sat, 12 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Open Redirect in Malcolm File‑Upload Handler |
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's browser to be redirected to an arbitrary external destination after completing an upload. | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-11T21:51:25.668Z
Reserved: 2026-09-11T21:00:09.301Z
Link: CVE-2026-90453
No data.
Status : Received
Published: 2026-09-11T22:16:47.630
Modified: 2026-09-11T22:16:47.630
Link: CVE-2026-90453
No data.
OpenCVE Enrichment
Updated: 2026-09-12T09:15:12Z