Vulnerability in Open edX Platform LTI Provider Implementation
CVE-2026-53636
4.7MEDIUM
What is CVE-2026-53636?
The Open edX Platform has a security issue in its LTI (Learning Tools Interoperability) Provider implementation that affects the validate_timestamp_and_nonce function. This vulnerability allows an attacker to intercept a valid LTI launch request and replay it multiple times without detection. Specifically, the implementation lacks proper validation for OAuth nonces and timestamps, potentially exposing the platform to unauthorized access and misuse. A fix has been implemented in commit 3a5ac85 to address this issue and enhance the security of the platform.
Affected Version(s)
openedx-platform < 3a5ac856c79557c5c74d8b3e6578f289d7cceecd
