Description
A critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed.
Advisory: https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-223g-f5mq-gw33
Recommendation
Update the openlearnx package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.4
- Patched version(s): 2.0.4
References
Could your website be exposed too?
SmartScanner can check your website for OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery - CVE-2026-34751
- Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery - payload - CVE-2026-34751
- OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment - CVE-2026-41900
- jsrsasign: Negative Exponent Handling Leads to Signature Verification Bypass - CVE-2026-4602


