Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-223g-f5mq-gw33

Опубликовано: 13 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover

Overview

A critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed.

Advisory: https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-223g-f5mq-gw33

Пакеты

Наименование

openlearnx

npm
Затронутые версииВерсия исправления

< 2.0.4

2.0.4

EPSS

Процентиль: 11%
0.00207
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-287
CWE-347

Связанные уязвимости

nvd
2 месяца назад

OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. This vulnerability is fixed in 2.0.4.

EPSS

Процентиль: 11%
0.00207
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-287
CWE-347