CVE-2025-47942: Learners on edX Platform can download python_lib.zip

Published May 21, 2025
·
Updated

The Open edX Platform is a learning management platform. Prior to commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, edxapp has no built-in protection against downloading the pythonlib.zip asset from courses, which is a concern since it often contains custom grading code or answers to course problems. This potentially affects any course using custom Python-graded problem blocks. The openedx/configuration repo has had a patch since 2016 in the form of an nginx rule, but this was only intended as a temporary mitigation. As the configuration repo has been deprecated and we have not been able to locate any similar protection in Tutor, it is likely that most deployments have no protection against pythonlib.zip being downloaded. The recommended mitigation, implemented in commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, restricts pythonlib.zip downloads to just the course team and site staff/superusers.

Affected Software

1 affected component
Open edX edxapp<commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba

Event History

May 21, 2025
CVE Published
via MITRE·09:15 PM
Data Sourced
via MITRE·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-47942?

The severity of CVE-2025-47942 is considered to be medium due to the potential exposure of sensitive course materials.

2

How do I fix CVE-2025-47942?

To fix CVE-2025-47942, upgrade edxapp to the commit version 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba or later.

3

What does CVE-2025-47942 affect?

CVE-2025-47942 affects the Open edX platform, specifically the edxapp component prior to the specified commit.

4

What are the risks associated with CVE-2025-47942?

CVE-2025-47942 poses risks of unauthorized downloading of the python_lib.zip, which may contain sensitive grading code or answers.

5

Is there a known exploit for CVE-2025-47942?

As of now, there are no reported exploits for CVE-2025-47942, but the vulnerability should still be addressed promptly.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203