CVE-2025-47942
Last modified
CVE-2025-47942 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Open edX Platform is a learning management platform. Prior to commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, edxapp has no built-in protection against downloading the python_lib.zip asset from courses, which is a concern since it often contains custom grading code or answers to course problems. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
The Open edX Platform is a learning management platform. Prior to commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, edxapp has no built-in protection against downloading the python_lib.zip asset from courses, which is a concern since it often contains custom grading code or answers to course problems. This potentially affects any course using custom Python-graded problem blocks. The openedx/configuration repo has had a patch since 2016 in the form of an nginx rule, but this was only intended as a temporary mitigation. As the configuration repo has been deprecated and we have not been able to locate any similar protection in Tutor, it is likely that most deployments have no protection against python_lib.zip being downloaded. The recommended mitigation, implemented in commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, restricts python_lib.zip downloads to just the course team and site staff/superusers.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-47942?
How severe is CVE-2025-47942?
How do I fix CVE-2025-47942?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-47937TYPO3 is an open source, PHP based web content management sy…5.3
- CVE-2025-47938TYPO3 is an open source, PHP based web content management sy…3.8
- CVE-2025-47939TYPO3 is an open source, PHP based web content management sy…5.4
- CVE-2025-4794A vulnerability was found in PHPGurukul Online Course Regist…9.8
- CVE-2025-47940TYPO3 is an open source, PHP based web content management sy…7.2
- CVE-2025-47941TYPO3 is an open source, PHP based web content management sy…7.2
- CVE-2025-47943Gogs is an open source self-hosted Git service. In applicati…6.3
- CVE-2025-47944Multer is a node.js middleware for handling `multipart/form-…7.5
- CVE-2025-47945Donetick an open-source app for managing tasks and chores. P…9.8
- CVE-2025-47946Symfony UX is an initiative and set of libraries to integrat…6.1
- CVE-2025-47947ModSecurity is an open source, cross platform web applicatio…7.5
- CVE-2025-47948Cocotais Bot is a QQ official robot framework based on qq-bo…7.2
Are you affected by CVE-2025-47942?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
