CVE-2026-39352: Frappe
High severity, CVSS 8.7. EPSS: 1.3% chance of exploitation in the next 30 days.
Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue is resolved in versions 16.15.0, 15.105.0 and above.
Affected products
- Frappe Frappe: before 15.105.0 (fixed in 15.105.0); from 15.106.0, before 16.15.0 (fixed in 16.15.0)
Published 2026-05-20. Last modified 2026-07-23.