Description
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by email. This issue is fixed in versions 16.23.0 and 15.112.0.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/frappe/frappe/security/advisories/GHSA-wcm9-vvcc-r8pr
X_Refsource_Misc x_refsource_misc
https://github.com/frappe/frappe/commit/0914acb998004b3878eb5cf57b765115305b49a6
X_Refsource_Misc x_refsource_misc
https://github.com/frappe/frappe/commit/b02c1aec2c75eb0819cc6730dd230c2acb0fa60d
Scores
CVSS v4
2.3
EPSS
0.0026
EPSS Percentile
17.4%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (2)
frappe/frappe
>= 15.0.0, < 15.109.0
frappe/frappe
>= 16.0.0-beta.1, < 16.19.0
Published
Aug 07, 2026
Tracked Since
Aug 08, 2026