Vulnerability Description
Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. This vulnerability is fixed in 15.84.0 and 14.99.0.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Frappe | Frappe | < 14.99.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-31877?
CVE-2026-31877 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract in...
How severe is CVE-2026-31877?
CVE-2026-31877 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-31877?
Check the references section above for vendor advisories and patch information. Affected products include: Frappe Frappe.