Critical severity9.0OSV Advisory· Published Dec 29, 2025· Updated Jun 17, 2026
CVE-2025-68929
CVE-2025-68929
Description
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/frappe/frappe/security/advisories/GHSA-qq98-vfv9-xmxhnvdThird Party Advisory
- github.com/frappe/frappe/releases/tag/v14.99.6nvdRelease Notes
- github.com/frappe/frappe/releases/tag/v15.88.1nvdRelease Notes
News mentions
0No linked articles in our index yet.