Back

HIGH

Frappe LMS: Path Traversal in SCORM File Serving

Published Sep 17, 2026

Description

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The renderer constructs and opens a server-side path without first confirming that its real path remains within public/scorm, allowing files outside the SCORM directory to be read when they are accessible to the server process. This issue is fixed in version 2.52.1.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 17, 2026
Updated Sep 18, 2026
Reserved Jun 12, 2026
CISA Vulnrichment
Updated Sep 18, 2026
NVD
Status Received
Modified Sep 18, 2026
Red Hat
Severity n/a
Public date n/a