CVE-2026-25126 - PolarLearn's unvalidated vote direction allows vote count manipulation

CVE-2026-25126 - PolarLearn's unvalidated vote direction allows vote count manipulation

CVE ID : CVE-2026-25126 Published : Jan. 29, 2026, 10:15 p.m. | 1 hour, 50 minutes ago Description : PolarLearn is a free and open-source learning program. Prior to version 0-PRERELEASE-15, the vote API route (`POST /api/v1/forum/vote`) trusts the JSON body’s `direction` value without runtime validation. TypeScript types are not enforced at runtime, so an attacker can send arbitrary strings (e.g., `

CVE Details

Published
Jan. 29, 2026