PT-2026-34824 · Th30D4Y+2 · Openlearn
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenLearnX versions prior to 2.0.3
Description
OpenLearnX is an open-source, decentralized learning and assessment platform. A remote code execution (RCE) issue exists in the code execution environment, which allows an attacker to escape the Python sandbox and execute arbitrary commands.
Recommendations
Update to version 2.0.3.
Exploit
Fix
RCE
OS Command Injection
Code Injection
Protection Mechanism Failure
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openlearn