QSearchQSearch

CVE-2026-41900

8.8 HIGH

OpenLearnX is an open-source, decentralized learning and assessment platform

Published: 2026-05-08 · Last updated: 2026-05-29

Severity and scoring

CVSS
8.8 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-250, CWE-284, CWE-693, CWE-78, CWE-94

Affected products

VendorProduct
th30d4yopenlearnx

Description

OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbitrary command execution. This issue has been patched in version 2.0.3.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-22313 The device has a webserver that exposes a REST API authenticated with a token on the management network (9.1 CRITICAL)
  • CVE-2026-53853 OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowe... (8.3 HIGH)
  • CVE-2026-53845 OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch path skip before-... (4.3 MEDIUM)
  • CVE-2026-44932 Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a ... (8.8 HIGH)
  • CVE-2026-24155 NVIDIA NeMo Framework for all platforms contains a code injection vulnerability (7.8 HIGH)