CVE-2026-82634: Frappe Unrestricted Render Template

Whitelisted endpoint passes a parameter to `frappe.render_template` without restricting access via `frappe.only_for`.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-82634-frappe-unrestricted-render-template --engine opengrep

Description

Whitelisted endpoint passes a parameter to `frappe.render_template` without restricting access via `frappe.only_for`.