Remote Code Execution Vulnerability in Frappe Framework Affects Login Security
CVE-2026-47194

8.6HIGH

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-47194?

The Frappe Framework, a full-stack web application framework, suffers from a vulnerability that allows remote attackers to exploit the magic login link feature. Specifically, the issue arises from the handling of the Host header in requests, which, if controlled by an attacker, can result in malicious login links being generated. When users click on these links, they are redirected to an attacker-controlled domain where their login tokens may be captured. This poses a significant risk to user accounts and data integrity. The vulnerability has been addressed in versions 15.108.0 and 16.18.3, ensuring that login link generation is secure against such exploits.

Affected Version(s)

frappe >= 16.0.0-beta.1, < 16.18.3 < 16.0.0-beta.1, 16.18.3

frappe < 15.108.0 < 15.108.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.