VYPR

Kolibri

by Learningequality

Source repositories

CVEs (1)

  • CVE-2026-48053Jun 11, 2026
    risk 0.00cvss epss

    ## Summary Several Kolibri API endpoints accept an unvalidated `baseurl` parameter and fetch attacker-controlled URLs from the Kolibri server, reflecting the response body back to the caller. The original report identified two endpoints on the `RemoteFacilityUser*` viewsets;…