Remote Code Execution Vulnerability in Frappe Framework Affects Login Security
CVE-2026-47194
What is CVE-2026-47194?
The Frappe Framework, a full-stack web application framework, suffers from a vulnerability that allows remote attackers to exploit the magic login link feature. Specifically, the issue arises from the handling of the Host header in requests, which, if controlled by an attacker, can result in malicious login links being generated. When users click on these links, they are redirected to an attacker-controlled domain where their login tokens may be captured. This poses a significant risk to user accounts and data integrity. The vulnerability has been addressed in versions 15.108.0 and 16.18.3, ensuring that login link generation is secure against such exploits.
Affected Version(s)
frappe >= 16.0.0-beta.1, < 16.18.3 < 16.0.0-beta.1, 16.18.3
frappe < 15.108.0 < 15.108.0
