CVE-2026-47199

LOW

Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE

Title source: cna
STIX 2.1

Description

Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites if database permissions are not well aligned and MySQL FILE privileges are available. This issue is fixed in versions 16.18.3 and 15.108.0.

Scores

CVSS v4 2.3
EPSS 0.0040
EPSS Percentile 32.8%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (2)
frappe/frappe < 15.108.0
frappe/frappe >= 16.0.0-beta.1, < 16.18.3
Published Jul 10, 2026
Tracked Since Jul 11, 2026