CVE-2026-50703: Frappe Framework
Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.
Affected products
- Frappe Frappe Framework: version 17.0.0-dev only
Published 2026-06-24. Last modified 2026-06-25.