CVE-2026-47194
8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point to an attacker-controlled domain and capture the login token when a recipient follows the link. This issue is fixed in versions 15.108.0 and 16.18.3.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| frappe | frappe | >= 16.0.0-beta.1, < 16.18.3 | affected |
| frappe | frappe | < 15.108.0 | affected |
Weaknesses
- CWE-346: CWE-346: Origin Validation Error
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.