Frappe Framework Path Traversal Vulnerability Leading to Arbitrary File Read

Vulnerability

A critical arbitrary file read vulnerability via path traversal has been identified in Frappe Framework versions prior to 15.105.0 and 16.15.0. This vulnerability allows for unauthorized access to files on the server.

Impact

Exploitation of this vulnerability could lead to unauthorized reading of files on the server, potentially allowing attackers to access sensitive information.

Remediation

Users are advised to upgrade to Frappe Framework versions 16.15.0, 15.105.0 or above.

Added: May 20, 2026, 8:46 PM
Updated: May 20, 2026, 8:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
7.6
remediation
7.7
relevance
8.9
threat
0.1
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.