CVE-2026-47199 UNKNOWN

CVE-2026-47199

Published: 2026-07-10

Description

Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites if database permissions are not well aligned and MySQL FILE privileges are available. This issue is fixed in versions 16.18.3 and 15.108.0.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…