GHSL-2026-012: Unauthorized Data Exposure via REST API Link Expansion in Frappe - CVE-2026-39351
Frappe v15.96.0 contains a vulnerability in its REST API, allowing attackers to bypass doctype restrictions via v1 REST document read with expandlinks leaking linked document data without permission checks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2026-012?
GHSL-2026-012 has a risk score of 57, indicating a moderate severity level.
What is the nature of the vulnerability in GHSL-2026-012?
GHSL-2026-012 involves unauthorized data exposure via REST API link expansion in Frappe, allowing data leaks without permission checks.
How do I fix GHSL-2026-012?
To fix GHSL-2026-012, update Frappe to the latest version that addresses the unauthorized data exposure issue.
Which version of Frappe is affected by GHSL-2026-012?
Frappe v15.96.0 is the specific version affected by the vulnerability identified in GHSL-2026-012.
What impact does GHSL-2026-012 have on data security?
GHSL-2026-012 can lead to unauthorized access to linked document data, compromising the confidentiality of sensitive information.