CVE-2026-63654

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow approvals because the endpoint is not restricted to POST. An attacker can induce an authenticated victim browser to submit an approval action with the victim privileges. No released fixed version is available as of this review.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-20 19:16

Updated : 2026-09-10 20:48


NVD link : CVE-2026-63654

Mitre link : CVE-2026-63654

CVE.ORG link : CVE-2026-63654


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)