CVE-2024-27105: Frappe

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, granting less privileged users permission to delete or clone a file. Versions 14.66.3 and 15.16.0 contain a patch for this issue. No known workarounds are available.

Affected products

  • Frappe Frappe: before 14.66.3 (fixed in 14.66.3); from 15.0.0, before 15.16.0 (fixed in 15.16.0)

Published 2024-03-21. Last modified 2026-06-17.