PT-2026-95711 · Unknown · Open Edx Platform

CVE-2026-85272

·

Published

2026-09-18

·

Updated

2026-09-19

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Open edX Platform versions Aspen.1 through Ulmo Open edX Platform versions Aspen.1 through Verawood.1
Description In the file openedx/core/lib/extract archive.py, the is bad path function validates safe extractall targets by comparing resolved path strings using startswith instead of comparing path components. A course author or staff user with course import permissions can exploit this by submitting a crafted .tar.gz archive through the import olx flow initiated by the cms.djangoapps.contentstore.views.import export.import handler endpoint. This allows an archive member to escape into a sibling course staging directory that shares the attacker's base64 directory prefix, resulting in limited cross-tenant file corruption. Zip archives are not practically affected as ZipFile.extractall strips parent traversal segments.
Recommendations Update to version Ulmo. Update to version Verawood.1.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85272
GHSA-6CMM-8875-5PCW

Affected Products

Open Edx Platform