SQL Injection Vulnerability in Frappe Framework
CVE-2026-31877
9.3CRITICAL
What is CVE-2026-31877?
Frappe Framework versions prior to 15.84.0 and 14.99.0 are susceptible to SQL injection due to improper handling of specially crafted requests at specific endpoints. This flaw can enable attackers to perform unauthorized actions, potentially allowing them to extract sensitive information from the database that should remain protected. Updates have been issued in the mentioned versions to address this security concern.
Affected Version(s)
frappe >= 15.0.0, < 15.84.0 < 15.0.0, 15.84.0
frappe < 14.99.0 < 14.99.0
