Medium severity5.4NVD Advisory· Published Mar 11, 2026· Updated Jun 17, 2026
CVE-2026-31879
CVE-2026-31879
Description
Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation and improper permission checks, users could modify other user's private workspaces. Specially crafted requests could lead to stored XSS here. This vulnerability is fixed in 14.100.2, 15.101.0, and 16.10.0.
Affected products
3Patches
Vulnerability mechanics
References
1- github.com/frappe/frappe/security/advisories/GHSA-qmhf-rgx2-8p25nvdVendor Advisory
News mentions
0No linked articles in our index yet.