VDB
Sign up
—

PYSEC-2026-1390

Frappe has possibility of SQL injection due to improper validations

Quick fix

PYSEC-2026-1390 — frappe: upgrade to the fixed version with the command below.

pip install --upgrade 'frappe>=14.89.0'

Details

### Impact An SQL Injection vulnerability has been identified in Frappe Framework which could allow a malicious actor to access sensitive information.

### Workarounds Upgrading is required, no other workaround is present.

### Credits

Thanks to Thanh of Calif.io for reporting the issue

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/frappe
Introduced in: 0Fixed in: 14.89.0
Fixpip install --upgrade 'frappe>=14.89.0'

References