CVE-2026-50699: Frappe Framework

Medium severity, CVSS 4.6. EPSS: 0.5% chance of exploitation in the next 30 days.

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form.

Affected products

  • Frappe Frappe Framework: version 17.0.0-dev only

Published 2026-06-24. Last modified 2026-06-25.