CVE-2026-39405: Frappe has Path Transversal via SCORM
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to write files outside the intended directory. This issue has been resolved in version 2.50.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappe Learning Management System (LMS)to a version that resolves this vulnerability.Fixed in 2.50.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39405?
CVE-2026-39405 has been classified as a high-severity vulnerability due to its potential for unauthorized file manipulation.
How do I fix CVE-2026-39405?
To mitigate CVE-2026-39405, upgrade to Frappe LMS version 2.50.1 or later.
Who is affected by CVE-2026-39405?
CVE-2026-39405 affects all users of Frappe LMS versions 2.50.0 and earlier with course editing roles.
What can an attacker do with CVE-2026-39405?
An attacker can exploit CVE-2026-39405 to upload SCORM ZIP packages that may write files outside the intended directory.
Is there any workaround for CVE-2026-39405?
There is no known workaround for CVE-2026-39405; upgrading to the latest version is the best course of action.