{"id":"CVE-2026-41320","summary":"Frappe HR has possibility of SQL Injection due to improper field sanitization","details":"Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. Versions 15.54.0 and 14.38.1 contain a patch. No known workarounds are available.","aliases":["GHSA-745c-5q8r-vgj2"],"modified":"2026-07-15T01:49:04.991886203Z","published":"2026-04-21T19:34:16.753Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41320.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41320.json"},{"type":"ADVISORY","url":"https://github.com/frappe/hrms/security/advisories/GHSA-745c-5q8r-vgj2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41320"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/frappe/hrms","events":[{"introduced":"0"},{"fixed":"0bfc80f0ec64a034359307290575b0e1d040ad09"},{"introduced":"d7a4769bf4786b5a244b5b1a77b6be9ddf0547b3"},{"fixed":"cdaa5e02abd62988d9aee51e339cb2cd03b4bf41"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:frappe:frappe_hr:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"14.38.1"},{"introduced":"15.0.0"},{"fixed":"15.54.0"}]}}],"versions":["v14.38.0","v15.53.0","v15.52.5","v14.37.13","v15.52.4","v15.52.3","v15.52.2","v15.52.1","v15.52.0","v15.51.0","v14.37.12","v15.50.3","v15.50.2","v15.50.1","v15.50.0","v14.37.11","v15.49.2","v14.37.10","v15.49.1","v15.49.0","v14.37.9","v14.37.8","v15.48.1","v15.48.0","v15.47.8","v14.37.7","v15.47.7","v14.37.6","v15.47.6","v15.47.5","v14.37.5","v15.47.4","v15.47.3","v14.37.4","v14.37.3","v15.47.2","v15.47.1","v15.47.0","v15.46.1","v15.46.0","v15.45.3","v14.37.2","v15.45.2","v14.37.1","v15.45.1","v15.45.0","v14.37.0","v14.36.12","v15.44.2","v15.44.1","v15.44.0","v14.36.11","v15.43.1","v14.36.10","v15.43.0","v15.42.3","v15.42.2","v14.36.9","v15.42.1","v15.42.0","v15.41.0","v14.36.8","v15.40.0","v14.36.7","v15.39.2","v15.39.1","v14.36.6","v15.39.0","v14.36.5","v15.38.3","v14.36.4","v15.38.2","v14.36.3","v15.38.1","v14.36.2","v15.38.0","v15.37.2","v14.36.1","v15.37.1","v14.36.0","v14.35.4","v15.37.0","v15.36.1","v15.36.0","v14.35.3","v15.35.3","v14.35.2","v14.35.1","v15.35.2","v15.35.1","v14.35.0","v15.35.0","v15.34.0","v15.33.2","v14.34.2","v14.34.1","v15.33.1","v15.33.0","v14.34.0","v15.32.2","v15.32.1","v15.32.0","v15.31.0","v14.33.0","v15.30.0","v14.32.0","v14.31.0","v15.29.0","v14.30.1","v15.28.3","v15.28.2","v15.28.1","v15.28.0","v15.27.2","v15.27.1","v15.27.0","v14.30.0","v15.26.0","v14.29.3","v15.25.2","v15.25.1","v14.29.2","v14.29.1","v15.25.0","v15.24.0","v14.29.0","v15.23.1","v14.28.8","v15.23.0","v14.28.7","v15.22.3","v14.28.6","v15.22.2","v14.28.5","v15.22.1","v14.28.4","v15.22.0","v14.28.3","v14.28.2","v15.21.2","v15.21.1","v14.28.1","v15.21.0","v14.28.0","v15.20.3","v14.27.1","v15.20.2","v14.27.0","v14.26.2","v15.20.1","v15.20.0","v14.26.1","v15.19.0","v14.26.0","v15.18.0","v15.17.0","v14.25.0","v15.16.0","v14.24.2","v15.15.0","v15.14.2","v14.24.1","v14.24.0","v15.14.1","v15.14.0","v15.13.1","v14.23.0","v15.13.0","v14.22.1","v15.12.0","v14.22.0","v15.11.1","v14.21.6","v15.11.0","v14.21.5","v15.10.0","v14.21.4","v14.21.3","v15.9.2","v14.21.2","v15.9.1","v14.21.1","v15.9.0","v15.8.0","v14.21.0","v15.7.1","v14.20.1","v15.7.0","v14.20.0","v15.6.0","v14.19.0","v15.5.0","v14.18.1","v15.4.1","v15.4.0","v14.18.0","v15.3.0","v14.17.0","v15.2.0","v14.16.1","v14.16.0","v15.1.0","v14.15.0","v15.0.0","v14.14.0","v14.13.1","v14.13.0","v14.12.1","v14.12.0","v14.11.1","v14.11.0","v14.10.6","v14.10.5","v14.10.4","v14.10.3","v14.10.2","v14.10.1","v14.10.0","v14.9.0","v14.8.0","v14.7.0","v14.6.2","v14.6.1","v14.6.0","v14.5.1","v14.5.0","v14.4.5","v14.4.4","v14.4.3","v14.4.2","v14.4.1","v14.4.0","v14.3.4","v14.3.3","v14.3.2","v14.3.1","v14.3.0","v14.2.4","v14.2.3","v14.2.2","v14.2.1","v14.2.0","v14.1.3","v14.1.2","v14.1.1","v14.1.0","v14.0.3","v14.0.2","v14.0.1","v14.0.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41320.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}