CVE-2026-31878 | Frappe up to 14.100.0/15.99.x/16.5.x Request server-side request forgery (EUVD-2026-11290)
A vulnerability was found in Frappe up to 14.100.0/15.99.x/16.5.x and classified as critical. This issue affects some unknown processing of the component Request Handler. The manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-31878. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.