Directory Traversal Vulnerability in Open edX Platform by Open edX
CVE-2026-85272
What is CVE-2026-85272?
The Open edX Platform has a flaw in its extraction process for .tar.gz archives that may allow a malicious course author or staff member to exploit a directory traversal vulnerability. When these users import crafted archives, they have the potential to manipulate the import mechanism to escape the intended target directories and access sibling course staging areas, thereby leading to limited cross-tenant file corruption. This vulnerability affects versions from Aspen.1 to Ulmo, and has been addressed in subsequent releases. Standard Zip archives remain unaffected due to built-in protections against directory traversal.
Affected Version(s)
openedx-platform >= release/aspen.1, < release/ulmo.4 < release/aspen.1, release/ulmo.4
openedx-platform >= release/aspen.1, < release/verawood.1 < release/aspen.1, release/verawood.1
