Impact
The flaw in Frappe allows an attacker to alter the file path used by the Chrome PDF Generator, enabling traversal of directory boundaries and inclusion of arbitrary local files. This can reveal confidential server data or expose sensitive configuration files and may lead to further compromise. The weakness is tied to CWE‑22, where unsafe file path handling permits the abuse described.
Affected Systems
Any installation of the Frappe framework running a version earlier than 16.18.3 is vulnerable. The advisory explicitly states that the issue was resolved in release 16.18.3, so all earlier releases must be reviewed and updated if present in production environments.
Risk and Exploitability
The CVSS score of 7.1 places the vulnerability in the medium severity range. Although the EPSS score is less than 1%, indicating a low probability of exploitation, the potential impact on confidentiality and the possibility of further exploitation keep the risk non‑negligible. The advisory does not specify the attack vector; but based on the description, it is inferred that the flaw could be exploited via the Chrome PDF Generator by supplying a crafted path. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment