Rhino Security Labs disclosed multiple vulnerabilities in Frappe LMS that can be chained to give a student-level attacker remote code execution on the LMS server after an administrator views the attacker’s profile. The chain combines stored cross-site scripting in profile bio previews, tracked as CVE-2026-34606, with a SCORM-upload path traversal flaw, CVE-2026-39405, allowing a privileged course creator to write extracted archive content outside the intended assets directory and overwrite application files.
The stored XSS stems from BeautifulSoup get_text() concatenating otherwise benign text fragments into executable HTML without re-sanitizing the output. Researchers also reported CVE-2026-46546, a meta-tag injection flaw that enables open redirects. Frappe LMS v2.44.0 was confirmed vulnerable; the issues are fixed in v2.50.1, and organizations should upgrade promptly and review LMS servers for unauthorized file changes or suspicious profile content.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The Frappe LMS Project posted CVE-2026-39405 for SCORM-upload path traversal, CVE-2026-34606 for stored XSS, and CVE-2026-46546 for meta-tag injection leading to open redirect.
Frappe stated that all reported vulnerabilities had been fixed. Frappe LMS version 2.50.1 is identified as the fixed version, while version 2.44.0 was confirmed vulnerable.
Frappe acknowledged the researchers' disclosure of the reported Frappe LMS vulnerabilities.
Researchers initially disclosed multiple Frappe LMS vulnerabilities to Frappe, including flaws that could be chained from student-level access to remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcerhinosecuritylabs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.