Security Advisory

CVE-2026-42219

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-10 21:26:30
Last updated 2026-07-13 14:15:58
Assigner GitHub_M
CVSS score 6.9
State PUBLISHED

Description

Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was possible due to lack of hardening. This issue is fixed in versions 16.19.0 and 15.109.0.