CVE-2025-68929
EUVD-2025-20560229.12.2025, 15:16
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| frappe | frappe | 𝑥 < 14.99.6 |
| frappe | frappe | 15.0.0 ≤ 𝑥 < 15.88.1 |
𝑥
= Vulnerable software versions