Unvalidated URL Parameter Vulnerability in Kolibri Education Platform
CVE-2026-48053
5.8MEDIUM
What is CVE-2026-48053?
The Kolibri education platform has a vulnerability that affects various API endpoints, allowing for unvalidated baseurl parameters. This flaw enables attackers to control URL requests, leading to potentially harmful data exposure as the response body is reflected back to the user. The issue was discovered primarily in the RemoteFacilityUser* viewsets but further analysis uncovered additional endpoints susceptible to similar reflection attacks. The vulnerability was addressed in version 0.19.4, highlighting the importance of stringent input validation processes in safeguarding user data.
Affected Version(s)
kolibri < 0.19.4
