MEDIUM
learningequality
CVE published 2026-08-17
CVE-2026-48053
Kolibri, an offline-first education platform, had several API endpoints that accepted an unvalidated `baseurl` parameter, allowing attackers to fetch and reflect arbitrary URLs. This issue was fixed in version 0.19.4. The vulnerability, identified as CVE-2026-48053, posed a significant risk as it enabled attackers to potentially exploit SSRF (Server-Side Request Forgery) vulnerabilities. Defenders should [truncated]