CVE-2026-81731 | Frappe up to 16.32.0 Workspace Link Widget links_widget.js LinksWidget.set_body Description cross site scripting

SecurityVulns

A vulnerability was found in Frappe up to 16.32.0. It has been declared as problematic. The affected element is the function LinksWidget.set_body of the file frappe/public/js/frappe/widgets/links_widget.js of the component Workspace Link Widget. The manipulation of the argument Description results in cross site scripting.

This vulnerability is reported as CVE-2026-81731. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More