NONE · 0

CVE-2026-54343

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer....

Vulnerability Description

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The renderer constructs and opens a server-side path without first confirming that its real path remains within public/scorm, allowing files outside the SCORM directory to be read when they are accessible to the server process. This issue is fixed in version 2.52.1.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-54343?

CVE-2026-54343 is a documented vulnerability. Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer....

How severe is CVE-2026-54343?

CVSS scoring is not yet available for CVE-2026-54343. Check NVD for updates.

Is there a patch for CVE-2026-54343?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.