OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 0.9%
exploitation probability
0.9%top 42% of all CVEs
observed exploitation
nono source reports it
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbitrary command execution. This issue has been patched in version 2.0.3.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
th30d4y · OpenLearnX