Executive brief
Frappe, a web application framework, contained a security flaw in its PDF generation component. An attacker could exploit this to access sensitive files on the server that should normally be restricted. This could lead to the exposure of private system data or configuration files. The issue has been resolved in version 16.18.3.
Technical details
A path traversal and local file inclusion (LFI) vulnerability exists in the Frappe web framework's Chrome PDF Generator utility. The flaw resides in the 'intercept_request_for_local_resources' function within 'frappe/utils/pdf_generator/page.py', which failed to properly restrict local resource access. An authenticated attacker with low privileges can provide crafted paths to include or read arbitrary files from the server's local filesystem. The fix, introduced in version 16.18.3, implements stricter validation to ensure the system only loads files from the site's designated public files and assets directories.
Affected products
- Frappe Frappe < 16.18.3
Timeline
- 2026-04-18: patched: Initial fix merged into develop branch
- 2026-05-20: patched: Backported fix released in version 16.18.3
- 2026-07-10: advisory: CVE-2026-41482 published
References
- https://github.com/frappe/frappe/commit/11066591ed7aa91a7b742f3f689277a90e620ce0
- https://github.com/frappe/frappe/commit/46841f7fde3954e1d3b3a7e248a6d6022343e657
- https://github.com/frappe/frappe/pull/38643
- https://github.com/frappe/frappe/pull/39396
- https://github.com/frappe/frappe/releases/tag/v16.18.3
- https://github.com/frappe/frappe/security/advisories/GHSA-234v-jfr8-v2f8