CVE-2026-41482

Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in the Chrome PDF Generator. This issue is fixed in version 16.18.3.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-10 22:16

Updated : 2026-07-13 19:17


NVD link : CVE-2026-41482

Mitre link : CVE-2026-41482

CVE.ORG link : CVE-2026-41482


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')