A pool manager can frontrun borrow with updateInterestRate by setting a really high interest rate. Then they can switch it back to normal. That way a user won't have a clue about astronomical interest rates until they have to pay the loan.
Mitigation steps:
Add aggreedInterestRate inside borrow and compare it with the one in the pool
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.