CVE-2026-31878

MEDIUM
5.0CVSS v3
CVSS v2
0.04% EPSS (exploit probability)
CWE-918CWE

Description

Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a crafted request to an endpoint which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 14.100.1, 15.100.0, and 16.6.0.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references