CVE-2026-47199

Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites if database permissions are not well aligned and MySQL FILE privileges are available. This issue is fixed in versions 16.18.3 and 15.108.0.
CVSS

No CVSS.

Configurations

No configuration.

History

10 Jul 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 22:16

Updated : 2026-07-13 18:05


NVD link : CVE-2026-47199

Mitre link : CVE-2026-47199

CVE.ORG link : CVE-2026-47199


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')