CVE-2026-31878: Frappe
Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.
Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a crafted request to an endpoint which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 14.100.1, 15.100.0, and 16.6.0.
Affected products
- Frappe Frappe: before 14.100.1 (fixed in 14.100.1); from 15.0.0, before 15.100.0 (fixed in 15.100.0); from 16.0.0, before 16.6.0 (fixed in 16.6.0)
Published 2026-03-11. Last modified 2026-06-17.