Junglewise Threat Intelligence

CVE-2026-49391: Frappe Data Import stored cross-site scripting in column headers

CVE-2026-49391 · Severity: info · Published 2026-08-06

Technologies: Frappe. Vendors: Frappe.

Executive brief

Frappe is a web application framework used to build enterprise business applications. A flaw in the Data Import feature allows an authenticated user to inject malicious scripts through column headers that execute when other users view import previews or results, potentially compromising access to sensitive data or account credentials.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Frappe's Data Import module. The vulnerability exists because column headers imported from data files are not properly escaped before being rendered in the preview and results interfaces. An authenticated importer can inject JavaScript code in column headers; this payload persists and executes in the browser of any other user who views the import interface. The attack requires authentication to the Frappe application and prior knowledge of the data import mechanism, but does not require user interaction beyond normal use of the import feature. Patches were released in versions 16.19.0 and 15.109.0 that add proper escaping of column headers.

Affected products

  • Frappe Frappe before 15.109.0 and 16.19.0

Timeline

  • 2026-08-06: disclosed
  • 2026-08-06: patched: Fixed in versions 15.109.0 and 16.19.0

References

Related threats