Frappe has Possibility of Remote Code Execution due to improper validation
Package
Affected versions
< 14.91.0
>= 15.0.0, < 15.52.0
Patched versions
14.91.0
15.52.0
Description
Published by the National Vulnerability Database
Mar 25, 2025
Published to the GitHub Advisory Database
Mar 25, 2025
Reviewed
Mar 25, 2025
Last updated
Mar 30, 2025
Impact
A system user was able to create certain documents in a specific way that could lead to RCE.
Workarounds
There's no workaround, an upgrade is required.
Credits
Thanks to Thanh of Calif.io for reporting the issue
References