CVE-2025-68929: Frappe
Critical severity, CVSS 9.0. EPSS: 0.5% chance of exploitation in the next 30 days.
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.
Affected products
- Frappe Frappe: before 14.99.6 (fixed in 14.99.6); from 15.0.0, before 15.88.1 (fixed in 15.88.1)
Published 2025-12-29. Last modified 2026-06-17.