Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4mj9-pf4r-cqrc | Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset |
Mon, 17 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and fetch attacker-controlled URLs from the Kolibri server, reflecting the response body back to the caller. The original report identified two endpoints on the `RemoteFacilityUser*` viewsets; remediation review found two further reflection points on the same pattern. The GET endpoint was unauthenticated. Version 0.19.4 fixes the vulnerability. | |
| Title | Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T19:53:05.341Z
Reserved: 2026-05-20T18:15:53.579Z
Link: CVE-2026-48053
Updated: 2026-08-17T19:52:43.164Z
Status : Received
Published: 2026-08-17T18:16:39.660
Modified: 2026-08-17T20:16:43.347
Link: CVE-2026-48053
No data.
OpenCVE Enrichment
Updated: 2026-08-17T19:45:04Z
Github GHSA