An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter implementations interpolate stored values into raw HTML attributes and element content without escaping
This issue affects Frappe: 16.10.0.
References
| Link | Resource |
|---|---|
| https://fluidattacks.com/es/advisories/sabina | Exploit Third Party Advisory |
| https://github.com/frappe/frappe | Product |
| https://github.com/frappe/frappe/pull/38796 | Issue Tracking Patch |
Configurations
History
14 May 2026, 21:24
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fluidattacks.com/es/advisories/sabina - Exploit, Third Party Advisory | |
| References | () https://github.com/frappe/frappe - Product | |
| References | () https://github.com/frappe/frappe/pull/38796 - Issue Tracking, Patch | |
| CPE | cpe:2.3:a:frappe:frappe:16.10.0:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| First Time |
Frappe
Frappe frappe |
27 Apr 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
22 Apr 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-22 21:17
Updated : 2026-05-14 21:24
NVD link : CVE-2026-3837
Mitre link : CVE-2026-3837
CVE.ORG link : CVE-2026-3837
JSON object : View
Products Affected
frappe
- frappe
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
