Frappe 是一个全栈 Web 应用框架。在版本 16.31.0 及更早版本中, 文件中的 函数在对通过 参数提供的字典进行解析之前,仅检查该字典是否包含被禁止的标准字段和子表字段。然而,由于类型混淆(type confusion)漏洞,经过身份验证的攻击者可以利用此问题,通过客户端接口批量赋值受保护的字段。截至本审查时,尚未发布任何修复版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-66001 | 8.5 HIGH | Frappe: Improper Authorization in OAuth2 Consent Endpoint |
| CVE-2026-66002 | 6.9 MEDIUM | Frappe: User Enumeration via PDDR |
| CVE-2026-63654 | 6.9 MEDIUM | Frappe: Unauthenticated Workflow approval via confirm_action |
| CVE-2026-53569 | 5.3 MEDIUM | Frappe: Missing authorization in toggle_like and mark_as_seen |
No comments yet