VYPR
High severity7.5NVD Advisory· Published Apr 24, 2026· Updated Apr 30, 2026

CVE-2026-41317

CVE-2026-41317

Description

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).press.api.account.create_api_secret is prone to CSRF-like exploits. This endpoint writes to database and it is also accessible via GET method. The patch in commit 52ea2f2d1b587be0807557e96f025f47897d00fd restricts method to POST.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Frappe/Press2 versions
    cpe:2.3:a:frappe:press:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:frappe:press:*:*:*:*:*:*:*:*range: <0.9.0
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.