Path Traversal Vulnerability in Frappe Framework Affects Multiple Versions
CVE-2026-42219

6.9MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
10 July 2026

What is CVE-2026-42219?

The Frappe framework, a full-stack web application framework, contains a vulnerability that allows path traversal through the 'download_backups' feature due to insufficient security hardening. This flaw could potentially enable unauthorized users to access sensitive files stored on the server. To mitigate this risk, users are advised to upgrade to versions 16.19.0 or 15.109.0, where the vulnerability has been addressed. Keeping your software updated is crucial to safeguard applications from such security threats.

Affected Version(s)

frappe < 15.109.0 < 15.109.0

frappe >= 16.0.0-beta.1, < 16.19.0 < 16.0.0-beta.1, 16.19.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.