CVE-2026-54343
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The renderer constructs and opens a server-side path without first confirming that its real path remains within public/scorm, allowing files outside the SCORM directory to be read when they are accessible to the server process. This issue is fixed in version 2.52.1.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| frappe | lms | < 2.52.1 | affected |
Weaknesses
- CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
References
- https://github.com/frappe/lms/security/advisories/GHSA-3mq2-3c8v-m92j
- https://github.com/frappe/lms/pull/2299
- https://github.com/frappe/lms/commit/e1b425ed5bf0fc9c373efc1ba235c7c70e23d465
- https://github.com/frappe/lms/releases/tag/v2.52.1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.