Unrated severityOSV Advisory· Published Dec 22, 2025· Updated Dec 22, 2025
CVE-2025-67289
CVE-2025-67289
Description
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.