Security Advisory

CVE-2026-39352

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-20 19:27:01
Last updated 2026-05-21 14:25:31
Assigner GitHub_M
CVSS score 8.7
State PUBLISHED

Description

Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue is resolved in versions 16.15.0, 15.105.0 and above.