CVE-2026-85271
Last modified
CVE-2026-85271 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawood.1, the add_additional_attributes_to_notifications function in openedx/core/djangoapps/notifications/email/utils.py assigns notification content without sanitizing discussion-title values produced by get_notification_content in openedx/core/djangoapps/notifications/base_notification.py. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawood.1, the add_additional_attributes_to_notifications function in openedx/core/djangoapps/notifications/email/utils.py assigns notification content without sanitizing discussion-title values produced by get_notification_content in openedx/core/djangoapps/notifications/base_notification.py. An enrolled student can place CSS-capable markup in the post_title value supplied by lms/djangoapps/discussion/rest_api/discussions_notifications.py. Digest and batched-email rendering then passes that value through openedx/core/djangoapps/notifications/templates/notifications/digest_content.html as safe HTML, allowing email-open tracking and content spoofing or phishing when another learner opens a CSS-rendering client. The immediate-email path is not affected because it strips title markup and renders a separately sanitized body. This issue is fixed in Ulmo and Verawood.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| openedx | openedx-platform | >= release/redwood.1, < release/ulmo.4 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-85271?
How severe is CVE-2026-85271?
How do I fix CVE-2026-85271?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8524Out of bounds write in WebAudio in Google Chrome prior to 14…8.8
- CVE-2026-85241A weakness has been identified in SpecterOps BloodHound up t…6.3
- CVE-2026-85242PlaywrightCapture contains a server-side request forgery (SS…6.9
- CVE-2026-8525Heap buffer overflow in ANGLE in Google Chrome on Mac prior …8.3
- CVE-2026-8526Out of bounds write in WebRTC in Google Chrome prior to 148.…8.8
- CVE-2026-8527Insufficient validation of untrusted input in Downloads in G…8.8
- CVE-2026-85272Open edX Platform enables the authoring and delivery of onli…4.3
- CVE-2026-85274InvoicePlane is a self-hosted open source application for ma…6.5
- CVE-2026-85279Notepad++ is a free and open-source source code editor. Prio…8.6
- CVE-2026-8528Insufficient validation of untrusted input in SiteIsolation …4.3
- CVE-2026-85288Notepad++ is a free and open-source source code editor. Prio…6.7
- CVE-2026-85289InvoicePlane is a self-hosted open source application for ma…6.5
Are you affected by CVE-2026-85271?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
