HIGH8.8
GHSA-8h25-q488-4hxw
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
Quick fix
GHSA-8h25-q488-4hxw — openlearnx: upgrade to the fixed version with the command below.
npm install openlearnx@2.0.3Details
## Overview
A critical Remote Code Execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbitrary command execution. The issue has been fixed.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-8h25-q488-4hxw[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-41900[ADVISORY]
- https://github.com/th30d4y/OpenLearnX/commit/14765d7d1856d564747c55c5412e2f38feab079e[WEB]
- https://github.com/th30d4y/OpenLearnX[PACKAGE]
- https://github.com/th30d4y/OpenLearnX/releases/tag/v2.0.3-security-fix[WEB]