CVE-2026-55852: Frappe: TarSlip RCE in Package Import
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently checked before extraction. This issue is fixed in versions 16.23.0 and 15.112.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 16.23.0 - Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.112.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55852?
The severity of CVE-2026-55852 is rated as high with a score of 8.6.
How do I fix CVE-2026-55852?
To fix CVE-2026-55852, upgrade Frappe to version 16.23.0 or 15.112.0 or later.
What type of vulnerability is CVE-2026-55852?
CVE-2026-55852 is categorized as a Path Traversal vulnerability leading to Remote Code Execution.
Which versions of Frappe are affected by CVE-2026-55852?
Versions prior to 16.23.0 and 15.112.0 of Frappe are affected by CVE-2026-55852.
What is the impact of CVE-2026-55852?
CVE-2026-55852 allows an attacker to execute arbitrary code on the server due to insufficient checks during package import.