—
PYSEC-2026-1392
Frappe vulnerable to information disclosure leading to account takeover
Quick fix
PYSEC-2026-1392 — frappe: upgrade to the fixed version with the command below.
pip install --upgrade 'frappe>=14.89.0'Details
### Impact Making crafted requests could lead to information disclosure that could further lead to account takeover.
### Workarounds There's no workaround to fix this without upgrading.
### Credits Thanks to Thanh of Calif.io for reporting the issue
Are you affected?
Enter the version of the package you're using.