Executive brief
Frappe is a web application framework used to build business software. A security flaw allows any logged-in user to view private files that they should not have permission to see by guessing the file's storage path. This could lead to the unauthorized exposure of sensitive business documents or user data.
Technical details
An improper access control vulnerability (CWE-284) exists in the Frappe Framework's file handling component. The root cause is a failure to properly enforce authorization checks on private file paths, allowing authenticated users to bypass intended restrictions. An attacker with low-privileged network access can retrieve sensitive files by predicting or brute-forcing their file paths. The vulnerability is resolved in version 16.17.4; no known workarounds exist.
Affected products
- Frappe Frappe Framework < 16.17.4
Timeline
- 2026-05-27: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: CVE published to NVD