VDB
Sign up
—

PYSEC-2026-1392

Frappe vulnerable to information disclosure leading to account takeover

Quick fix

PYSEC-2026-1392 — frappe: upgrade to the fixed version with the command below.

pip install --upgrade 'frappe>=14.89.0'

Details

### Impact Making crafted requests could lead to information disclosure that could further lead to account takeover.

### Workarounds There's no workaround to fix this without upgrading.

### Credits Thanks to Thanh of Calif.io for reporting the issue

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/frappe
Introduced in: 0Fixed in: 14.89.0
Fixpip install --upgrade 'frappe>=14.89.0'

References