---
id: CVE-2026-47185
title: Frappe is a full-stack web application framework
summary: >-
  Frappe is a full-stack web application framework. Prior to 16.18.0, the
  Workspace Save API accepts a controlled workspace identifier from any
  authenticated user without enforcing workspace ownership, allowing
  modification of another user…
severity: none
cwe:
  - CWE-79
  - CWE-863
published: '2026-08-06'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:51:43.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47185'
references:
  - url: >-
      https://github.com/frappe/frappe/commit/8ef9e9076293c3f567b734ac9b1b81e63b805ab5
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/frappe/security/advisories/GHSA-mcr4-jc52-ww6x'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00411
epssPercentile: 0.32533
ingestedAt: '2026-09-08T21:11:12.269Z'
---

## Overview

Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership, allowing modification of another user's private workspace and persistent script injection. This issue is fixed in version 16.18.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
