PT-2026-95710 · Unknown · Open Edx Platform
CVE-2026-85271
·
Published
2026-09-18
·
Updated
2026-09-27
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Open edX Platform versions Redwood through Ulmo and Verawood.1
Description
The
add additional attributes to notifications function in openedx/core/djangoapps/notifications/email/utils.py assigns notification content without sanitizing discussion-title values produced by get notification content in openedx/core/djangoapps/notifications/base notification.py. An enrolled student can inject CSS-capable markup into the post title value supplied by lms/djangoapps/discussion/rest api/discussions notifications.py. During digest and batched-email rendering, this value is processed through openedx/core/djangoapps/notifications/templates/notifications/digest content.html as safe HTML. This allows for email-open tracking, content spoofing, or phishing when another learner uses a CSS-rendering client.Recommendations
Update to Ulmo or Verawood.1.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Edx Platform