Remote Code Execution in Frappe Web Application Framework
CVE-2026-55852
8.6HIGH
What is CVE-2026-55852?
The Frappe application framework experienced a vulnerability that allowed remote code execution via Package Import prior to versions 16.23.0 and 15.112.0. The issue stemmed from insufficient validation of tarfile members before extraction, which could be exploited by an attacker. The vulnerability has been addressed in the recent updates, ensuring that such extraction processes are now securely validated, thereby safeguarding the applications built on this framework.
Affected Version(s)
frappe < 15.112.0 < 15.112.0
frappe >= 16.0.0-beta.1, < 16.23.0 < 16.0.0-beta.1, 16.23.0
