Vulnerability Description
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.account.create_api_secret` is prone to CSRF-like exploits. This endpoint writes to database and it is also accessible via GET method. The patch in commit 52ea2f2d1b587be0807557e96f025f47897d00fd restricts method to POST.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Frappe | Press | < 0.9.0 |
Related Weaknesses (CWE)
References
- https://github.com/frappe/press/commit/52ea2f2d1b587be0807557e96f025f47897d00fdPatch
- https://github.com/frappe/press/security/advisories/GHSA-q4wg-jrr8-vpwfVendor Advisory
FAQ
What is CVE-2026-41317?
CVE-2026-41317 is a vulnerability with a CVSS score of 7.5 (HIGH). Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.account.create_api_secret` is prone to CSRF-like explo...
How severe is CVE-2026-41317?
CVE-2026-41317 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41317?
Check the references section above for vendor advisories and patch information. Affected products include: Frappe Press.