CVE-2026-47199: Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE
Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, checksafesqlquery permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites if database permissions are not well aligned and MySQL FILE privileges are available. This issue is fixed in versions 16.18.3 and 15.108.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 16.18.3 - Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.108.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47199?
CVE-2026-47199 has a severity rating of low with a CVSS score of 4.0.
How do I fix CVE-2026-47199?
To resolve CVE-2026-47199, upgrade to Frappe version 16.18.3 or 15.108.0 or later.
What type of vulnerability is CVE-2026-47199 classified as?
CVE-2026-47199 is classified as an SQL Injection vulnerability.
What impact does CVE-2026-47199 have on self-hosted sites?
CVE-2026-47199 can potentially allow unauthorized file access if database permissions and MySQL FILE privileges are not properly configured.
When was CVE-2026-47199 published?
CVE-2026-47199 was published on July 10, 2026.