HIGH

CVE-2026-47194

2026-08-06 CVSS v4.0
CVSS
8.6

Description

Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point to an attacker-controlled domain and capture the login token when a recipient follows the link. This issue is fixed in versions 15.108.0 and 16.18.3.

Weakness (CWE)

CWE-346

EPSS Score

0.2%
Probability of exploitation in next 30 days
10.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE