CVE-2026-48127: Frappe: Arbitrary Attachment Injection via add_attachments and upload_file
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as addattachments. This issue is fixed in versions 16.20.0 and 15.110.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.20.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.110.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48127?
CVE-2026-48127 has a medium severity rating of 5.3 based on the CVSS scoring system.
How do I fix CVE-2026-48127?
To mitigate CVE-2026-48127, update Frappe to version 16.20.0 or later, or to version 15.110.0 or later.
What does CVE-2026-48127 refer to?
CVE-2026-48127 refers to an arbitrary attachment injection vulnerability in Frappe that allows users without write access to attach files improperly.
Which versions of Frappe are affected by CVE-2026-48127?
Versions of Frappe prior to 16.20.0 and 15.110.0 are affected by CVE-2026-48127.
Can CVE-2026-48127 be exploited without special privileges?
Yes, CVE-2026-48127 can be exploited by users without write access, as it affects how files can be attached through certain API endpoints.