Directory Traversal Vulnerability in Open edX Platform by Open edX
CVE-2026-85272

4.3MEDIUM

Key Information:

Vendor

Openedx

Vendor
CVE Published:
18 September 2026

What is CVE-2026-85272?

The Open edX Platform has a flaw in its extraction process for .tar.gz archives that may allow a malicious course author or staff member to exploit a directory traversal vulnerability. When these users import crafted archives, they have the potential to manipulate the import mechanism to escape the intended target directories and access sibling course staging areas, thereby leading to limited cross-tenant file corruption. This vulnerability affects versions from Aspen.1 to Ulmo, and has been addressed in subsequent releases. Standard Zip archives remain unaffected due to built-in protections against directory traversal.

Affected Version(s)

openedx-platform >= release/aspen.1, < release/ulmo.4 < release/aspen.1, release/ulmo.4

openedx-platform >= release/aspen.1, < release/verawood.1 < release/aspen.1, release/verawood.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.