Executive brief
Frappe, a web application framework, contains a vulnerability that allows unauthorized users to discover the internal structure of its database. By exploiting a specific web endpoint, an attacker can map out how data is organized, which is often a precursor to more advanced attacks like data theft. This issue has been resolved in the latest software updates.
Technical details
A vulnerability in Frappe Framework (prior to versions 15.107.2 and 16.17.4) allows for database schema enumeration. The flaw exists in a specific web endpoint that fails to properly restrict access or sanitize requests, enabling an unauthenticated remote attacker to gather information about the database structure (CWE-200). This information disclosure can be used to facilitate further targeted attacks against the application's data layer. The issue is addressed in versions 15.107.2 and 16.17.4.
Affected products
- Frappe Frappe Framework < 15.107.2, < 16.17.4
Timeline
- 2026-06-03: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: NVD publication date