GHSA-223g-f5mq-gw33Medium

OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover

Published
May 13, 2026
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Overview

A critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed.

Advisory: https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-223g-f5mq-gw33

🎯 Affected products1

  • npm/openlearnx:< 2.0.4

🔗 References (4)