CVE-2026-42219: Frappe: Path Traversal via /backups Route
Published Jul 10, 2026
·Updated
Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via downloadbackups was possible due to lack of hardening. This issue is fixed in versions 16.19.0 and 15.109.0.
Affected Software
1 affected component
Frappe frappe>16.19.0<=16.19.0, >15.109.0<=15.109.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 16.19.0 - Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.109.0
Event History
Jul 10, 2026
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42219?
The severity of CVE-2026-42219 is medium with a CVSS score of 6.9.
2
How do I fix CVE-2026-42219?
To fix CVE-2026-42219, upgrade to Frappe versions 16.19.0 or 15.109.0 or later.
3
What type of vulnerability is CVE-2026-42219?
CVE-2026-42219 is a path traversal vulnerability.
4
In which versions of Frappe is CVE-2026-42219 present?
CVE-2026-42219 is present in Frappe versions prior to 16.19.0 and 15.109.0.
5
What is affected by CVE-2026-42219?
CVE-2026-42219 affects the Frappe web application framework's backups route.