Description
A critical Remote Code Execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbitrary command execution. The issue has been fixed.
Recommendation
Update the openlearnx package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.3
- Patched version(s): 2.0.3
References
Could your website be exposed too?
SmartScanner can check your website for OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment and gives you actionable findings to investigate.
Start a free scanRelated Issues
- DbGate: Unauthenticated Remote Code Execution via JSON Script Runner - CVE-2026-47668
- Authenticated Remote Code Execution via loadReader functionName code injection in DbGate - CVE-2026-47670
- Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified - CVE-2026-69255
- Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix) - CVE-2026-73649


