CVE-2025-68929
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with spec
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution.
Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.
CRITICAL · CVSS 9
EPSS 0.00094
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0