Junglewise Threat Intelligence

CVE-2026-39352: Frappe Framework arbitrary file read via path traversal

CVE-2026-39352 · Severity: info · CVSS 8.7 · Published 2026-05-20

Vendors: Frappe.

Executive brief

Frappe, a web application framework used to build business software like ERPNext, contains a vulnerability that allows unauthorized access to files on the server. An attacker could exploit this to read sensitive system configuration files or application data, potentially leading to further compromise of the hosting environment. Organizations using Frappe should update to the latest patched versions to prevent data exposure.

Technical details

A path traversal vulnerability (CWE-22) exists in the Frappe web framework due to insufficient validation of file paths when the system includes external files. An unauthenticated remote attacker can exploit this by sending specially crafted requests containing directory traversal sequences (e.g., ../) to access files outside of the intended application directory. This can result in the disclosure of sensitive system files, environment variables, or source code. The vulnerability is addressed in versions 15.105.0 and 16.15.0 by implementing stricter security checks on file paths.

Affected products

  • Frappe Frappe Framework < 15.105.0, < 16.15.0

Timeline

  • 2026-04-14: patched: Version 16.15.0 released with security fix
  • 2026-05-11: advisory: GitHub Security Advisory published
  • 2026-05-20: disclosed: CVE published to NVD dataset

References