PT-2026-95710 · Unknown · Open Edx Platform

CVE-2026-85271

·

Published

2026-09-18

·

Updated

2026-09-27

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Open edX Platform versions Redwood through Ulmo and Verawood.1
Description The add additional attributes to notifications function in openedx/core/djangoapps/notifications/email/utils.py assigns notification content without sanitizing discussion-title values produced by get notification content in openedx/core/djangoapps/notifications/base notification.py. An enrolled student can inject CSS-capable markup into the post title value supplied by lms/djangoapps/discussion/rest api/discussions notifications.py. During digest and batched-email rendering, this value is processed through openedx/core/djangoapps/notifications/templates/notifications/digest content.html as safe HTML. This allows for email-open tracking, content spoofing, or phishing when another learner uses a CSS-rendering client.
Recommendations Update to Ulmo or Verawood.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85271
GHSA-RV5W-F4R5-H77G

Affected Products

Open Edx Platform