IA Squad
SearchPT

kolibri

python · kolibriHeads-up

Kolibri SSRF via unvalidated baseurl parameter in multiple API endpoints

Multiple Kolibri API endpoints accepted an unvalidated `baseurl` parameter, allowing server-side request forgery (SSRF) and respon

12 Jun 2026 · schedule it