{"id":"CVE-2026-48127","title":"Frappe is a full-stack web application framework","summary":"Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16…","severity":"none","cwe":["CWE-862"],"published":"2026-07-10","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48127","references":[{"url":"https://github.com/frappe/frappe/commit/4bf27db101c34bd542a760290fc0775efa5cd0e4","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/commit/b1c86042e6f85986f35365c80bb1d102ff1cd0e4","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/commit/fee1af6d89910f6b174fd094184060aeb641d07d","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/pull/39407","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/pull/39550","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/pull/39553","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/releases/tag/v15.110.0","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/releases/tag/v16.20.0","label":"security-advisories@github.com"},{"url":"https://github.com/frappe/frappe/security/advisories/GHSA-fwrv-4rw4-97fw","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00614,"epssPercentile":0.47131,"ingestedAt":"2026-07-11T22:16:00.387Z","slug":"CVE-2026-48127","body":"## Overview\n\nFrappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16.20.0 and 15.110.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}