PT-2026-95711 · Unknown · Open Edx Platform
CVE-2026-85272
·
Published
2026-09-18
·
Updated
2026-09-19
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Open edX Platform versions Aspen.1 through Ulmo
Open edX Platform versions Aspen.1 through Verawood.1
Description
In the file
openedx/core/lib/extract archive.py, the is bad path function validates safe extractall targets by comparing resolved path strings using startswith instead of comparing path components. A course author or staff user with course import permissions can exploit this by submitting a crafted .tar.gz archive through the import olx flow initiated by the cms.djangoapps.contentstore.views.import export.import handler endpoint. This allows an archive member to escape into a sibling course staging directory that shares the attacker's base64 directory prefix, resulting in limited cross-tenant file corruption. Zip archives are not practically affected as ZipFile.extractall strips parent traversal segments.Recommendations
Update to version Ulmo.
Update to version Verawood.1.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Edx Platform