Executive brief
OpenLearnX is a learning platform that uses JSON Web Tokens (JWT) for user authentication. A vulnerability in JWT signature verification allowed attackers to forge authentication tokens and gain unauthorized access to user accounts without valid credentials. This could result in account takeover, unauthorized data access, and compromised student or instructor accounts across the platform.
Technical details
The vulnerability stems from improper verification of JWT cryptographic signatures in OpenLearnX's authentication mechanism (CWE-347, CWE-287). The backend failed to properly validate JWT signatures, allowing an attacker to forge valid tokens by either disabling signature checks or manipulating token claims. No authentication is required to exploit this—an attacker can craft a malicious JWT, send it with requests to the API, and the backend will accept it as valid, granting full account access. This is a network-reachable vulnerability with no user interaction required. The issue was patched in version 2.0.4 and affects all versions prior to 2.0.3.
Affected products
- th30d4y OpenLearnX <2.0.4
Timeline
- 2026-05-13: disclosed: OSV advisory published
- 2026-05-08: advisory: GitHub security advisory GHSA-223g-f5mq-gw33 published
- 2026-05-08: patched: Version 2.0.4 released with fix
- 2026-05-27: kev added: CVE-2026-44720 published by NVD