Ghostwire

CVE-2026-3673: An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim...

UNKNOWN CVSS 0.0

Published: April 22, 2026 | Last Modified: April 22, 2026

Description

An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where tags are rendered. The vulnerable renderer interpolates tag content into HTML attributes and element content without escaping. This issue affects Frappe: 16.10.10.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References