CVE-2026-47194
Received Received - Intake

Temporary Magic Login Link Host Header Injection in Frappe Framework

Vulnerability report for CVE-2026-47194, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: GitHub, Inc.

Description

Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point to an attacker-controlled domain and capture the login token when a recipient follows the link. This issue is fixed in versions 15.108.0 and 16.18.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
frappe frappe to 15.108.0 (exc)
frappe frappe to 16.18.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Frappe allows an attacker to manipulate the Host header in requests to generate temporary magic login links. The system uses this header to create login URLs sent via email. By controlling the Host header, an attacker can make these links point to a domain they control, enabling them to intercept login tokens when victims click the malicious links.

Impact Analysis

If you use Frappe versions before 15.108.0 or 16.18.3, an attacker could trick you into clicking a fake login link. This could lead to unauthorized account access if you enter credentials on the attacker's site. Sensitive data or actions performed after login could be compromised.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or health data, violating GDPR's data protection principles or HIPAA's security requirements. Organizations may face compliance breaches, legal penalties, or reputational damage if user data is exposed due to this issue.

Mitigation Strategies

Upgrade Frappe to version 15.108.0 or 16.18.3 or later to address the vulnerability in magic login link generation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47194. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart