Workflow Approval Endpoint Vulnerability in Frappe
CVE-2026-63654
6.9MEDIUM
What is CVE-2026-63654?
The Frappe Framework, specifically versions up to 16.31.0, contains a security vulnerability in the bulk_workflow_approval endpoint found in frappe/model/workflow.py. This endpoint inadequately restricts state-changing operations to POST requests, allowing the potential for an attacker to exploit the system by tricking an authenticated user into initiating approval actions with their own privileges. As a result, this could lead to unauthorized changes within workflow processes. Currently, there are no updates available to remediate this issue.
Affected Version(s)
frappe <= 16.31.0
