Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe frappe |
|
| Vendors & Products |
Frappe
Frappe frappe |
Thu, 20 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow approvals because the endpoint is not restricted to POST. An attacker can induce an authenticated victim browser to submit an approval action with the victim privileges. No released fixed version is available as of this review. | |
| Title | Frappe: Unauthenticated Workflow approval via confirm_action | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-20T19:47:38.338Z
Reserved: 2026-07-17T14:47:08.031Z
Link: CVE-2026-63654
No data.
Status : Received
Published: 2026-08-20T19:16:57.570
Modified: 2026-08-20T19:16:57.570
Link: CVE-2026-63654
No data.
OpenCVE Enrichment
Updated: 2026-08-20T19:30:05Z
-
CWE-352
Cross-Site Request Forgery (CSRF)