PT-2026-79106 · Frappe · Frappe

CVE-2026-63654

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Frappe versions 16.31.0 and earlier
Description The frappe.model.workflow.bulk workflow approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow approvals because it is not restricted to POST. This allows an attacker to induce an authenticated victim's browser to submit an approval action using the victim's privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63654
GHSA-CGWF-XGPH-HXGM

Affected Products

Frappe