CVE-2026-41900: TH30D4Y Openlearnx
Critical severity, CVSS 10.0. EPSS: 1.1% chance of exploitation in the next 30 days.
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbitrary command execution. This issue has been patched in version 2.0.3.
Affected products
- TH30D4Y Openlearnx: version 2.0.1 only
Published 2026-05-08. Last modified 2026-06-17.