OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
Description
Published to the GitHub Advisory Database
May 13, 2026
Reviewed
May 13, 2026
Published by the National Vulnerability Database
May 27, 2026
Last updated
Jun 8, 2026
Overview
A critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed.
Advisory: GHSA-223g-f5mq-gw33
References