—
PYSEC-2026-1390
Frappe has possibility of SQL injection due to improper validations
Quick fix
PYSEC-2026-1390 — frappe: upgrade to the fixed version with the command below.
pip install --upgrade 'frappe>=14.89.0'Details
### Impact An SQL Injection vulnerability has been identified in Frappe Framework which could allow a malicious actor to access sensitive information.
### Workarounds Upgrading is required, no other workaround is present.
### Credits
Thanks to Thanh of Calif.io for reporting the issue
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/frappe/frappe/security/advisories/GHSA-3hj6-r5c9-q8f3[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-30212[ADVISORY]
- https://github.com/frappe/frappe/commit/27f13437db161a173137d91cd07d0f9287d7c556[WEB]
- https://github.com/frappe/frappe/commit/2ebd88520ecfa9bb7d3392b7de8c8f94a86ec05c[WEB]
- https://github.com/frappe/frappe[PACKAGE]
- https://pypi.org/project/frappe[PACKAGE]
- https://github.com/advisories/GHSA-3hj6-r5c9-q8f3[ADVISORY]