Vulnerability Description
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbitrary command execution. This issue has been patched in version 2.0.3.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Th30D4Y | Openlearnx | 2.0.1 |
Related Weaknesses (CWE)
References
- https://github.com/th30d4y/OpenLearnX/commit/14765d7d1856d564747c55c5412e2f38feaPatch
- https://github.com/th30d4y/OpenLearnX/releases/tag/v2.0.3-security-fixRelease Notes
- https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-8h25-q488-4hxwVendor Advisory
FAQ
What is CVE-2026-41900?
CVE-2026-41900 is a vulnerability with a CVSS score of 8.8 (HIGH). OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was identified in the OpenLearnX code execution enviro...
How severe is CVE-2026-41900?
CVE-2026-41900 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41900?
Check the references section above for vendor advisories and patch information. Affected products include: Th30D4Y Openlearnx.