CVE-2026-55421: Open edX Platform: SSRF in Studio Video Download Endpoint

Published Sep 2, 2026
·
Updated

Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a server-side fetch using "requests.get(url, allowredirects=True)". The fetched bytes are then returned inside a ZIP response. This enables SSRF with response exfiltration. Redirect-following is enabled, and there is no timeout in the vulnerable fetch path. This issue has been patched via commit 00b7c3c.

Affected Software

1 affected component
Open edX Open edX Platform<00b7c3c

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Open edX Platform (Studio Video Download Endpoint) to a version that resolves this vulnerability.

    Patch 00b7c3c

Event History

Sep 2, 2026
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access does an attacker need to exploit this issue?

The vulnerability requires high privileges. An attacker must be able to submit values for files[].url to the Studio video download endpoint.

2

What can an attacker access through the vulnerable endpoint?

The server fetches the supplied URL and includes the fetched bytes in a ZIP response, allowing response data to be exfiltrated. Because redirects are followed, a supplied URL can redirect the server to another destination.

3

Are deployments affected by default?

The provided information does not identify a configuration prerequisite. The affected behavior is the endpoint's use of a user-supplied URL with server-side requests.get and redirect following.

4

What should be done if the installation cannot be patched immediately?

The available data does not provide a documented workaround. Prioritize restricting access to the affected Studio endpoint to trusted high-privilege users until the patch can be applied.

5

How can I determine whether an instance is vulnerable?

Check whether the deployment includes commit 00b7c3c. Versions or code states before that commit use the vulnerable fetch path; the issue is patched by that commit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203