A vulnerability, which was classified as problematic, has been found in Frappe 16.10.10. This affects an unknown function of the component Tag Handler. This manipulation of the argument _user_tags causes cross site scripting.
The identification of this vulnerability is CVE-2026-3673. It is possible to initiate the attack remotely. There is no exploit available.