Medium severity5.8GHSA Advisory· Published Aug 17, 2026· Updated Aug 17, 2026
CVE-2026-48053
CVE-2026-48053
Description
Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated baseurl parameter and fetch attacker-controlled URLs from the Kolibri server, reflecting the response body back to the caller. The original report identified two endpoints on the RemoteFacilityUser* viewsets; remediation review found two further reflection points on the same pattern. The GET endpoint was unauthenticated. Version 0.19.4 fixes the vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kolibriPyPI | < 0.19.4 | 0.19.4 |
Affected products
1- Range: <= 0.19.3
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.