CVE-2026-85271 | openedx Open edX Platform up to release/ulmo.3/ulmo.3 Email utils.py add_additional_attributes_to_notifications post_title cross site scripting

SecurityVulns

A vulnerability identified as problematic has been detected in openedx Open edX Platform up to release/ulmo.3/ulmo.3. This issue affects the function add_additional_attributes_to_notifications of the file openedx/core/djangoapps/notifications/email/utils.py of the component Email. Performing a manipulation of the argument post_title results in cross site scripting.

This vulnerability is cataloged as CVE-2026-85271. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More