VYPR
High severity8.8NVD Advisory· Published Mar 25, 2025· Updated Jun 17, 2026

CVE-2025-30213

CVE-2025-30213

Description

Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a specific way that could lead to remote code execution. Versions 14.9.1 and 15.52.0 contain a patch for the vulnerability. There's no workaround; an upgrade is required.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
frappePyPI
< 14.91.014.91.0
frappePyPI
>= 15.0.0, < 15.52.015.52.0

Affected products

3
  • Frappe/Frappe2 versions
    cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*range: <14.91.0
    • (no CPE)range: < 14.91.0
  • ghsa-coords
    Range: < 14.91.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.