CVE-2026-47185EPSS p33.2%
CVE-2026-47185CVE-2026-47185
Description
Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership, allowing modification of another user's private workspace and persistent script injection. This issue is fixed in version 16.18.0.
Scoring
| EPSS | 0.41% probability of exploitation · percentile 33.2% · 2026-10-06T12:00:23Z |
| Last modified | 2026-09-08 |