Description
Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate safe_extractall targets by comparing resolved path strings with startswith instead of comparing path components. A course author or staff user with course import permission can submit a crafted .tar.gz archive through the import_olx flow initiated by cms.djangoapps.contentstore.views.import_export.import_handler. An archive member can therefore escape into a sibling course staging directory whose name shares the attacker's base64 directory prefix, causing limited cross-tenant file corruption. Zip archives are not practically affected because ZipFile.extractall strips parent traversal segments, and the advisory does not establish arbitrary filesystem writes, file reads, or direct code execution. This issue is fixed in Ulmo and Verawood.1.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Limited cross-tenant file corruption
Action: Apply patch
AI Analysis

Impact

The vulnerability is a path traversal flaw that allows a user with course import privileges to craft an archive that resolves outside the intended course staging directory, enabling them to corrupt files in a sibling staging directory that shares an identical base‑64 prefix. This flaw does not provide arbitrary write or read access to the filesystem, nor does it allow code execution. The potential impact is limited to cross‑tenant file corruption within the import process.

Affected Systems

Affects the Open edX Platform, specifically versions from Aspen.1 up to and including Ulmo and Verawood.1. Users running older releases can submit crafted .tar.gz archives via the import_olx workflow in the cms.djangoapps.contentstore.views.import_export.import_handler endpoint. The issue is mitigated in releases Ulmo and Verawood.1, where the patch corrects the path validation logic.

Risk and Exploitability

With a CVSS score of 4.3, the vulnerability is considered low‑severity. The EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The typical attack requires a user with import permission, which is a privileged role. Because the flaw only permits limited file corruption and not arbitrary writes or execution, the risk profile remains low, though the ability to overwrite shared staging files could cause operational disruption in multi‑tenant environments.

Generated by OpenCVE AI on September 19, 2026 at 13:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to an Ulmo or Verawood.1 release that contains the path validation fix
  • If upgrading is delayed, restrict the import_olx operation to the smallest set of users that truly require course import capabilities, or disable the import feature for untrusted users
  • Monitor imported archive uploads for anomalous file paths and consider rejecting archives that contain path traversal sequences

Generated by OpenCVE AI on September 19, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Openedx
Openedx openedx-platform
Vendors & Products Openedx
Openedx openedx-platform

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate safe_extractall targets by comparing resolved path strings with startswith instead of comparing path components. A course author or staff user with course import permission can submit a crafted .tar.gz archive through the import_olx flow initiated by cms.djangoapps.contentstore.views.import_export.import_handler. An archive member can therefore escape into a sibling course staging directory whose name shares the attacker's base64 directory prefix, causing limited cross-tenant file corruption. Zip archives are not practically affected because ZipFile.extractall strips parent traversal segments, and the advisory does not establish arbitrary filesystem writes, file reads, or direct code execution. This issue is fixed in Ulmo and Verawood.1.
Title Open edX Platform: Path traversal via prefix-bypass in safe_extractall Path Validation
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Openedx Openedx-platform
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T16:13:29.175Z

Reserved: 2026-09-03T16:37:49.260Z

Link: CVE-2026-85272

cve-icon Vulnrichment

Updated: 2026-09-21T16:13:23.580Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T21:18:44.793

Modified: 2026-09-24T21:20:08.527

Link: CVE-2026-85272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:45:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')