LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-31878

frappe · frappe

Published
CVSS5
Severitymedium
WeaknessCWE-918
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Description

Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a crafted request to an endpoint which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 14.100.1, 15.100.0, and 16.6.0.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-31878

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-31878.