CVE-2026-50700
EUVD-2026-3879624.06.2026, 16:16
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function.
Awaiting analysis
This vulnerability is currently awaiting analysis.