PT-2026-95140 · Frappe · Frappe Lms

·

CVE-2026-54343

·

Published

2026-09-17

·

Updated

2026-09-23

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Frappe Learning Management System (LMS) versions prior to 2.52.1
Description A remote attacker can request a traversal path handled by the SCORMRenderer.render() function in lms/page renderers.py. The renderer constructs and opens a server-side path without verifying that the real path remains within the public/scorm directory, which allows the reading of files outside the SCORM directory that are accessible to the server process.
Recommendations Update to version 2.52.1.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54343
GHSA-3MQ2-3C8V-M92J

Affected Products

Frappe Lms