CVE-2026-3673: Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer
An authenticated attacker can store a crafted tag value in usertags and trigger JavaScript execution when a victim opens the list/report view where tags are rendered. The vulnerable renderer interpolates tag content into HTML attributes and element content without escaping. This issue affects Frappe: 16.10.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3673?
The severity of CVE-2026-3673 is considered high due to the potential for stored DOM-based XSS attacks.
How do I fix CVE-2026-3673?
To fix CVE-2026-3673, update Frappe Framework to a version that addresses the stored DOM XSS vulnerability.
Who is affected by CVE-2026-3673?
CVE-2026-3673 affects users of Frappe Framework version 16.10.0 and prior.
What is the impact of CVE-2026-3673?
The impact of CVE-2026-3673 includes potential unauthorized JavaScript execution leading to data theft or session hijacking.
Is authentication required to exploit CVE-2026-3673?
Yes, an attacker must be authenticated to exploit CVE-2026-3673 by storing a crafted tag value.