CVE-2026-85272 | openedx Platform up to verawood.0.x Archive Extraction extract_archive.py _is_bad_path path traversal
A vulnerability was found in openedx Platform up to verawood.0.x. It has been rated as problematic. This affects the function _is_bad_path of the file openedx/core/lib/extract_archive.py of the component Archive Extraction. This manipulation causes path traversal.
This vulnerability is tracked as CVE-2026-85272. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More