CVE-2026-85271 | openedx Open edX Platform up to release/ulmo.3/ulmo.3 Email utils.py add_additional_attributes_to_notifications post_title cross site scripting
A vulnerability identified as problematic has been detected in openedx Open edX Platform up to release/ulmo.3/ulmo.3. This issue affects the function add_additional_attributes_to_notifications of the file openedx/core/djangoapps/notifications/email/utils.py of the component Email. Performing a manipulation of the argument post_title results in cross site scripting.
This vulnerability is cataloged as CVE-2026-85271. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More