VYPR
Moderate severityNVD Advisory· Published Mar 25, 2025· Updated Mar 25, 2025

Frappe has Possibility of Remote Code Execution due to improper validation

CVE-2025-30213

Description

Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a specific way that could lead to remote code execution. Versions 14.9.1 and 15.52.0 contain a patch for the vulnerability. There's no workaround; an upgrade is required.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
frappePyPI
< 14.91.014.91.0
frappePyPI
>= 15.0.0, < 15.52.015.52.0

Affected products

2

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.