PT-2026-34841 · Frappe · Press

·

CVE-2026-41317

·

Published

2026-04-24

·

Updated

2026-04-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Press (affected versions not specified)
Description Press, a Frappe custom app used for managing infrastructure, subscriptions, marketplace, and software-as-a-service (SaaS), contains a flaw in the 'press.api.account.create api secret' endpoint. This endpoint allows database writes and is accessible via the GET method, making it susceptible to Cross-Site Request Forgery (CSRF) style exploits, where an attacker could trick a user into performing unintended actions.
Recommendations Restrict the 'press.api.account.create api secret' endpoint to only allow POST requests.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41317
GHSA-Q4WG-JRR8-VPWF

Affected Products

Press