PT-2026-34824 · Th30D4Y+2 · Openlearn

·

CVE-2026-41900

·

Published

2026-04-23

·

Updated

2026-05-09

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenLearnX versions prior to 2.0.3
Description OpenLearnX is an open-source, decentralized learning and assessment platform. A remote code execution (RCE) issue exists in the code execution environment, which allows an attacker to escape the Python sandbox and execute arbitrary commands.
Recommendations Update to version 2.0.3.

Exploit

Fix

RCE

OS Command Injection

Code Injection

Protection Mechanism Failure

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-41900
GHSA-8H25-Q488-4HXW

Affected Products

Openlearn