CVE-2026-39405
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to write files outside the intended directory. This issue has been resolved in version 2.50.1.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/frappe/lms/releases/tag/v2.50.1, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39405.json, https://github.com/frappe/lms/security/advisories/GHSA-mxh7-g3r7-g96h, https://nvd.nist.gov/vuln/detail/CVE-2026-39405