Skip to content

Path Traversal in SCORM File Serving

Critical
raizasafeel published GHSA-3mq2-3c8v-m92j Jun 4, 2026

Package

No package listed

Affected versions

<= 2.51.0

Patched versions

2.52.0

Description

Impact

  • Path traversal vulnerability in the SCORM file renderer lets attacker to read arbitrary files on the server.

Patches

  • File paths are now checked to stay within the SCORM directory before serving.

Acknowledgement

  • Credits to Aizzat Azman and Ahmed Reda

Severity

Critical

CVE ID

CVE-2026-54343

Weaknesses

No CWEs

Credits