VulnerabilityDeferred
CVE-2026-55852
Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently checked before extraction.
HIGH 8.6EPSS 0.68%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently checked before extraction. This issue is fixed in versions 16.23.0 and 15.112.0.
- CVSS 4.0
- 8.6 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Source
- security-advisories@github.com
References
- https://github.com/frappe/frappe/commit/3c75f13fd7d4441a880dd236450277dc37fcddfd
- https://github.com/frappe/frappe/commit/4772e3e7f72db43d48137af74fa77e5fce903223
- https://github.com/frappe/frappe/commit/57e527d933aeffaec0cd735838701792c848e3e7
- https://github.com/frappe/frappe/pull/38716
- https://github.com/frappe/frappe/pull/40044
- https://github.com/frappe/frappe/pull/40045
- https://github.com/frappe/frappe/releases/tag/v15.112.0
- https://github.com/frappe/frappe/releases/tag/v16.23.0
- https://github.com/frappe/frappe/security/advisories/GHSA-58w2-4cjg-hvp6
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.