# CVE-2026-3837

> Vulnerability · severity: **MEDIUM** (CVSS 5.4).

## Description

An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter implementations interpolate stored values into raw HTML attributes and element content without escaping

This issue affects Frappe: 16.10.0.

## Key facts

- **CVE ID:** CVE-2026-3837
- **Published:** 2026-04-22
- **CVSS severity:** MEDIUM
- **CVSS base score:** 5.4
- **CWE codes:** CWE-79

## Affected products

- `frappe:frappe`

## Primary sources

- NIST NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-3837

## Citation

> AI Analytics. CVE-2026-3837. Retrieved 2026-07-20 from https://api.ai-analytics.org/cve/CVE-2026-3837. Derived from NIST NVD. Licensed CC0.

---

*[Dataset catalog](https://api.ai-analytics.org/datasets/) · [AI Analytics](https://api.ai-analytics.org/) · CC0 1.0*