CVE-2026-42219EPSS p50.7%
CVE-2026-42219CVE-2026-42219
Description
Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was possible due to lack of hardening. This issue is fixed in versions 16.19.0 and 15.109.0.
Scoring
| EPSS | 0.68% probability of exploitation · percentile 50.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-13 |