VDB
Sign up
—

PYSEC-2026-1393

Frappe has Possibility of Remote Code Execution due to improper validation

Quick fix

PYSEC-2026-1393 — frappe: upgrade to the fixed version with the command below.

pip install --upgrade 'frappe>=14.91.0'

Details

### Impact A system user was able to create certain documents in a specific way that could lead to RCE.

### Workarounds There's no workaround, an upgrade is required.

### Credits Thanks to Thanh of Calif.io for reporting the issue

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/frappe
Introduced in: 0Fixed in: 14.91.0
Fixpip install --upgrade 'frappe>=14.91.0'

References