SQL Injection Vulnerability in Frappe Framework
CVE-2026-31877
9.3CRITICAL
What is CVE-2026-31877?
Frappe Framework versions prior to 15.84.0 and 14.99.0 are susceptible to SQL injection due to improper handling of specially crafted requests at specific endpoints. This flaw can enable attackers to perform unauthorized actions, potentially allowing them to extract sensitive information from the database that should remain protected. Updates have been issued in the mentioned versions to address this security concern.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
frappe >= 15.0.0, < 15.84.0 < 15.0.0, 15.84.0
frappe < 14.99.0 < 14.99.0
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
