PT-2026-34824 · Th30D4Y+1 · Openlearn

Krrazee

·

Published

2026-04-23

·

Updated

2026-05-09

·

CVE-2026-41900

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenLearnX versions prior to 2.0.3
Description OpenLearnX is an open-source, decentralized learning and assessment platform. A remote code execution (RCE) issue exists in the code execution environment, which allows an attacker to escape the Python sandbox and execute arbitrary commands.
Recommendations Update to version 2.0.3.

Fix

RCE

Improper Access Control

Protection Mechanism Failure

Code Injection

OS Command Injection

Related Identifiers

CVE-2026-41900
GHSA-8H25-Q488-4HXW

Affected Products

Openlearn