Unrated severityOSV Advisory· Published Dec 29, 2025· Updated Dec 29, 2025
Frappe may be vulnerable remote code execution due to server-side template injection
CVE-2025-68929
Description
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/frappe/frappe/releases/tag/v14.99.6mitrex_refsource_MISC
- github.com/frappe/frappe/releases/tag/v15.88.1mitrex_refsource_MISC
- github.com/frappe/frappe/security/advisories/GHSA-qq98-vfv9-xmxhmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.