GHSA-gq25-78jf-v78cLowCVSS 3.3

Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control

Published
November 26, 2025
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks.

🎯 Affected products1

  • pip/tutor:<= 20.0.2

🔗 References (6)