Junglewise Threat Intelligence

CVE-2026-35404: Open edX Platform open redirect in survey views

CVE-2026-35404 · Severity: medium · CVSS 4.7 · Published 2026-04-06

Technologies: Open edX Platform. Vendors: Open edX.

Executive brief

The Open edX Platform, a popular online learning system, contains a security flaw in its survey component. An attacker can create a specially crafted link that appears to be a legitimate part of the educational site but instead redirects logged-in students or staff to a malicious external website. This can be used in phishing campaigns to trick users into providing their login credentials or other sensitive information on a fake site that looks like the real platform.

Technical details

An open redirect vulnerability exists in the Open edX Platform's survey application. The 'view_survey' endpoint in 'lms/djangoapps/survey/views.py' accepts a 'redirect_url' GET parameter and passes it directly to 'HttpResponseRedirect()' without validation when a non-existent survey name is requested. Additionally, for valid surveys, the same unvalidated URL is stored in a hidden form field and subsequently used by client-side JavaScript ('location.href') after form submission. An attacker can exploit this by distributing a crafted URL to authenticated users. The vulnerability is fixed by ignoring user-supplied redirect URLs in the survey views and defaulting redirects to the user dashboard.

Affected products

  • openedx Open edX Platform <= master (all versions containing the survey app)

Timeline

  • 2026-04-02: advisory: Original GHSA advisory published
  • 2026-04-06: disclosed: CVE-2026-35404 published
  • 2026-04-02: patched: Fix committed to master branch

References

Related threats