Email Spoofing Vulnerability in Open edX Platform by Open edX
CVE-2026-85271
6.1MEDIUM
What is CVE-2026-85271?
The Open edX Platform has a vulnerability that allows an attacker to exploit the email notification system. Specifically, in versions from Redwood to Ulmo and Verawood.1, the add_additional_attributes_to_notifications function fails to properly sanitize discussion-title values. This lack of validation can lead to CSS-capable markup being inserted by enrolled students, enabling email open tracking and phishing attempts through malicious content. The vulnerability is mitigated in the latest releases: Ulmo and Verawood.1.
Affected Version(s)
openedx-platform >= release/redwood.1, < release/ulmo.4
