—
PYSEC-2026-1391
Frappe has possibility of SQL injection due to improper validations
Quick fix
PYSEC-2026-1391 — frappe: upgrade to the fixed version with the command below.
pip install --upgrade 'frappe>=14.93.2'Details
### Impact SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information.
### Workarounds Upgrading is required, no other workaround is present.
Are you affected?
Enter the version of the package you're using.