Frappe · Frappe Lms · CVE-2026-54343
**Name of the Vulnerable Software and Affected Versions**
Frappe Learning Management System (LMS) versions prior to 2.52.1
**Description**
A remote attacker can request a traversal path handled by the `SCORMRenderer.render()` function in lms/page renderers.py. The renderer constructs and opens a server-side path without verifying that the real path remains within the public/scorm directory, which allows the reading of files outside the SCORM directory that are accessible to the server process.
**Recommendations**
Update to version 2.52.1.