GHSL-2026-012: Unauthorized Data Exposure via REST API Link Expansion in Frappe - CVE-2026-39351
Frappe v15.96.0 contains a vulnerability (GHSL-2026-012) in its REST API, allowing attackers to bypass doctype restrictions via v1 REST document read with expandlinks leaking linked document data without permission checks.
Other sources
Frappe v15.96.0 contains a vulnerability in its REST API, allowing attackers to bypass doctype restrictions via v1 REST document read with expandlinks leaking linked document data without permission checks.
— GitHub Security Lab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.96.0Patch GHSL-2026-012 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-39351
Event History
Frequently Asked Questions
What is the severity of GHSL-2026-012?
GHSL-2026-012 has a risk score of 57, indicating a moderate severity level.
What is the nature of the vulnerability in GHSL-2026-012?
GHSL-2026-012 involves unauthorized data exposure via REST API link expansion in Frappe, allowing data leaks without permission checks.
How do I fix GHSL-2026-012?
To fix GHSL-2026-012, update Frappe to the latest version that addresses the unauthorized data exposure issue.
Which version of Frappe is affected by GHSL-2026-012?
Frappe v15.96.0 is the specific version affected by the vulnerability identified in GHSL-2026-012.
What impact does GHSL-2026-012 have on data security?
GHSL-2026-012 can lead to unauthorized access to linked document data, compromising the confidentiality of sensitive information.