Description
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The renderer constructs and opens a server-side path without first confirming that its real path remains within public/scorm, allowing files outside the SCORM directory to be read when they are accessible to the server process. This issue is fixed in version 2.52.1.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Read / Sensitive Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a path‑traversal flaw in the SCORM file rendering component of Frappe Learning Management System. An attacker can supply a crafted path that the renderer resolves without confirming it stays inside the public/scorm directory. This allows reading of arbitrary files on the server that the web process can access, leading to disclosure of potentially sensitive data. The flaw is rated CVSS 8.7, indicating a high severity impact.

Affected Systems

All instances of the frappe:lms product running a version earlier than 2.52.1 are affected. The patch was applied in version 2.52.1, making later releases immune.

Risk and Exploitability

The EPSS score of less than 1% suggests that, at the time of assessment, exploitation is unlikely, and the vulnerability is not currently listed in the CISA KEV catalog. Nevertheless, because it does not require authentication and can expose confidential files, organizations should consider the potential impact high. Attackers would need only the ability to send HTTP requests to the vulnerable SCORM endpoints to exploit the path traversal and read files on the server.

Generated by OpenCVE AI on September 19, 2026 at 01:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Frappe LMS installation to version 2.52.1 or later, where the path validation logic has been fixed.
  • If an immediate upgrade is not possible, restrict access to the SCORM file‑serving URLs to trusted networks or IP ranges using firewall or application‑level controls.
  • Ensure that any remaining instances of the SCORM renderer do not expose user‑supplied path components without proper sanitization and that the working directory is constrained to public/scorm.

Generated by OpenCVE AI on September 19, 2026 at 01:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Frappe
Frappe lms
Vendors & Products Frappe
Frappe lms

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The renderer constructs and opens a server-side path without first confirming that its real path remains within public/scorm, allowing files outside the SCORM directory to be read when they are accessible to the server process. This issue is fixed in version 2.52.1.
Title Frappe LMS: Path Traversal in SCORM File Serving
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:14:49.268Z

Reserved: 2026-06-12T19:23:22.317Z

Link: CVE-2026-54343

cve-icon Vulnrichment

Updated: 2026-09-18T20:14:46.082Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T22:17:00.390

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-54343

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')