Frappe · Frappe Lms · CVE-2026-39405
**Name of the Vulnerable Software and Affected Versions**
Frappe Learning Management System (LMS) versions prior to 2.50.1
**Description**
A user with a course editing role can upload a SCORM ZIP package to write files outside the intended directory. SCORM (Sharable Content Object Reference Model) is a set of technical standards for e-learning software to ensure content interoperability.
**Recommendations**
Update to version 2.50.1.