OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
- Severity:
- High
Description
A critical Remote Code Execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbitrary command execution. The issue has been fixed.
Recommendation
Update the openlearnx package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.3
- Patched version(s): 2.0.3
References
- GHSA-8h25-q488-4hxw
- CVE-2026-41900
- CWE-250
- CWE-284
- CWE-693
- CWE-78
- CWE-94
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- DbGate: Unauthenticated Remote Code Execution via JSON Script Runner - CVE-2026-47668
- Authenticated Remote Code Execution via loadReader functionName code injection in DbGate - CVE-2026-47670
- Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified - CVE-2026-69255
- Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix) - CVE-2026-73649
You might also like:
- Tags:
- npm
- openlearnx
Anything's wrong? Let us know Last updated on May 11, 2026


