CVE-2026-41430
EUVD-2026-2539124.04.2026, 04:16
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect parameter on login page is vulnerable to reflected XSS. The patch in commit 16d1b6ca2559f858a1de77bcb03fd7f1b81671c6 fixes the issue by restricting redirects to internal URLs only.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| frappe | press | 𝑥 < 0.16.0 |
𝑥
= Vulnerable software versions