CVE-2026-42219: Frappe
Medium severity, CVSS 6.9. EPSS: 0.7% chance of exploitation in the next 30 days.
Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was possible due to lack of hardening. This issue is fixed in versions 16.19.0 and 15.109.0.
Affected products
- Frappe Frappe: before 15.109.0 (fixed in 15.109.0); from 16.0.0-beta.1, before 16.19.0 (fixed in 16.19.0)
Published 2026-07-10. Last modified 2026-07-13.