VDB
Sign up
HIGH8.8

GHSA-8h25-q488-4hxw

OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment

Quick fix

GHSA-8h25-q488-4hxw — openlearnx: upgrade to the fixed version with the command below.

npm install openlearnx@2.0.3

Details

## Overview

A critical Remote Code Execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbitrary command execution. The issue has been fixed.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/openlearnx
Introduced in: 0Fixed in: 2.0.3
Fixnpm install openlearnx@2.0.3

References