CVE-2026-41581: Frappe Unvalidated Dict Key Childquery
Bypass of field validation for dictionary keys passed to ChildQuery. If dictionary keys from user-controlled JSON are passed without validation, attackers can inject SQL or call unauthorized SQL functions. Validate keys (e.g., check string properties or reject uppercase) before using them as field names.
greprules fetch cve-2026-41581-frappe-unvalidated-dict-key-childquery --engine opengrepDescription
Bypass of field validation for dictionary keys passed to ChildQuery. If dictionary keys from user-controlled JSON are passed without validation, attackers can inject SQL or call unauthorized SQL functions. Validate keys (e.g., check string properties or reject uppercase) before using them as field names.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.