OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
- Severity:
- Medium
Description
A critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed.
Advisory: https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-223g-f5mq-gw33
Recommendation
Update the openlearnx package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.4
- Patched version(s): 2.0.4
References
Related Issues
- Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery - CVE-2026-34751
- Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery - payload - CVE-2026-34751
- OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment - CVE-2026-41900
- jsrsasign: Negative Exponent Handling Leads to Signature Verification Bypass - CVE-2026-4602
You might also like:
- Tags:
- npm
- openlearnx
Anything's wrong? Let us know Last updated on June 08, 2026


