CVE-2026-39352: Frappe has an Arbitrary File Read via Path Traversal in render_include
Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue is resolved in versions 16.15.0, 15.105.0 and above.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 16.15.0 - Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.105.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39352?
CVE-2026-39352 has a critical severity level due to the potential for arbitrary file read through path traversal.
How do I fix CVE-2026-39352?
To fix CVE-2026-39352, upgrade Frappe to version 15.105.0 or 16.15.0 or above.
Which versions of Frappe are affected by CVE-2026-39352?
Frappe versions prior to 15.105.0 and 16.15.0 are affected by CVE-2026-39352.
What type of vulnerability is CVE-2026-39352?
CVE-2026-39352 is an arbitrary file read vulnerability caused by path traversal.
Is there a workaround for CVE-2026-39352?
There are no effective workarounds for CVE-2026-39352; upgrading Frappe is essential to mitigate the risk.