vulns.co
/
GKData.io MCP

GitHub Security Lab · 2 min read

Frappe: linked data must preserve document and field permissions

CVE-2026-39351 concerns related-document expansion in a REST response. Frappe loaded linked records without checking the caller’s permission and serialized them without field filtering. The research identifies disclosure of otherwise inaccessible documents in tested version 15.96.0.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Editorial lesson: authorization on a parent object cannot authorize every object reachable from it. Define response contracts that preserve both per-document access and field visibility during expansion. The maintainer advisory identifies patched releases 15.104.0 and 16.14.0; it does not describe the patch implementation.

Before reading

  • Basic API access-control concepts
  • Familiarity with server-side data processing

Context and limits

  • Requires a readable parent document whose expanded links reach records the caller cannot otherwise access; it does not establish unrestricted access to every document.
  • The publication explains the code-level disclosure mechanism but supplies no customer incident or measured data-loss evidence. Do not infer write access or account takeover.
  • Reported January 19, 2026; maintainer advisory published April 7; detailed research published April 24. Fix-release dates were not established by the reviewed sources.
  • The byline is Man Yue Mo. Discovery is credited to GitHub Security Lab Taskflow Agent, with human review by Peter Stöckli and Man Yue Mo. Learning prerequisites are editorial.

Related visual models

Sources and provenance

  1. GHSL-2026-012: Unauthorized Data Exposure via REST API Link Expansion in Frappe - CVE-2026-39351 GitHub Security Lab · reviewed 2026-10-03
  2. Unrestricted Doctype access via API exploit Frappe · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software