CVE-2026-54343EPSS p50.6%
CVE-2026-54343CVE-2026-54343
Description
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The renderer constructs and opens a server-side path without first confirming that its real path remains within public/scorm, allowing files outside the SCORM directory to be read when they are accessible to the server process. This issue is fixed in version 2.52.1.
Scoring
| EPSS | 0.68% probability of exploitation · percentile 50.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-23 |