CVE-2026-41482: Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generator
Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in the Chrome PDF Generator. This issue is fixed in version 16.18.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappe (Chrome PDF Generator)to a version that resolves this vulnerability.Fixed in 16.18.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41482?
The severity of CVE-2026-41482 is high with a CVSS score of 7.1.
How do I fix CVE-2026-41482?
To fix CVE-2026-41482, upgrade Frappe to version 16.18.3 or later.
What is CVE-2026-41482 about?
CVE-2026-41482 describes a vulnerability in Frappe that allows possible path traversal and local file inclusion through the Chrome PDF Generator.
Which versions of Frappe are affected by CVE-2026-41482?
Versions of Frappe prior to 16.18.3 are affected by CVE-2026-41482.
What type of vulnerability is CVE-2026-41482 classified as?
CVE-2026-41482 is classified as a Path Traversal vulnerability.