{"id":"CVE-2026-54343","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-54343","summary":"Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled…","details":"Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The renderer constructs and opens a server-side path without first confirming that its real path remains within public/scorm, allowing files outside the SCORM directory to be read when they are accessible to the server process. This issue is fixed in version 2.52.1.","published":"2026-09-17T22:17:00.390","modified":"2026-09-17T22:17:00.390","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/frappe/lms/commit/e1b425ed5bf0fc9c373efc1ba235c7c70e23d465","label":"frappe/lms@e1b425e"},"references":[{"type":"WEB","url":"https://github.com/frappe/lms/commit/e1b425ed5bf0fc9c373efc1ba235c7c70e23d465"},{"type":"WEB","url":"https://github.com/frappe/lms/pull/2299"},{"type":"WEB","url":"https://github.com/frappe/lms/releases/tag/v2.52.1"},{"type":"WEB","url":"https://github.com/frappe/lms/security/advisories/GHSA-3mq2-3c8v-m92j"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T22:17:00.390"}}