What is CVE-2026-48053?
This vulnerability exists in Kolibri education platform APIs before version 0.19.4 due to an unvalidated `baseurl` parameter. It allows an attacker to fetch arbitrary URLs through the server and reflect the response back (SSRF). Users are advised to upgrade to version 0.19.4.
Azərbaycanca: Bu boşluq Kolibri təhsil platformasının 0.19.4 versiyasından əvvəlki API-lərində `baseurl` parametrinin yoxlanılmaması səbəbindən yaranır. Bu, təcavüzkara server vasitəsilə ixtiyari URL-lərə sorğu göndərib cavabı geri qaytarmağa imkan verir (SSRF). İstifadəçilərə 0.19.4 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What type of attack does CVE-2026-48053 allow in the Kolibri platform?
Due to an unvalidated `baseurl` parameter, this vulnerability allows an attacker to fetch arbitrary URLs through the server and reflect the response back, resulting in an SSRF attack.
Which version is recommended to mitigate CVE-2026-48053?
Users are advised to upgrade to version 0.19.4 of the Kolibri education platform.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.