Vulnerabilities/

OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover

Severity:
Medium

Description

A critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed.

Advisory: https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-223g-f5mq-gw33

Recommendation

Update the openlearnx package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
openlearnx
Anything's wrong? Let us know Last updated on May 13, 2026