Vulnerability Description
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Frappe | Frappe | < 14.99.6 |
Related Weaknesses (CWE)
References
- https://github.com/frappe/frappe/releases/tag/v14.99.6Release Notes
- https://github.com/frappe/frappe/releases/tag/v15.88.1Release Notes
- https://github.com/frappe/frappe/security/advisories/GHSA-qq98-vfv9-xmxhThird Party Advisory
FAQ
What is CVE-2025-68929?
CVE-2025-68929 is a vulnerability with a CVSS score of 9.0 (CRITICAL). Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This ...
How severe is CVE-2025-68929?
CVE-2025-68929 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-68929?
Check the references section above for vendor advisories and patch information. Affected products include: Frappe Frappe.