CVE-2026-31878: Frappe

Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a crafted request to an endpoint which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 14.100.1, 15.100.0, and 16.6.0.

Affected products

  • Frappe Frappe: before 14.100.1 (fixed in 14.100.1); from 15.0.0, before 15.100.0 (fixed in 15.100.0); from 16.0.0, before 16.6.0 (fixed in 16.6.0)

Published 2026-03-11. Last modified 2026-06-17.