CVE-2026-39352: Frappe

High severity, CVSS 8.7. EPSS: 1.3% chance of exploitation in the next 30 days.

Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue is resolved in versions 16.15.0, 15.105.0 and above.

Affected products

  • Frappe Frappe: before 15.105.0 (fixed in 15.105.0); from 15.106.0, before 16.15.0 (fixed in 16.15.0)

Published 2026-05-20. Last modified 2026-07-23.