Unrated severityOSV Advisory· Published Dec 29, 2025· Updated Dec 29, 2025
Frappe may be vulnerable remote code execution due to server-side template injection
CVE-2025-68929
Description
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/frappe/frappe/releases/tag/v14.99.6mitrex_refsource_MISC
- github.com/frappe/frappe/releases/tag/v15.88.1mitrex_refsource_MISC
- github.com/frappe/frappe/security/advisories/GHSA-qq98-vfv9-xmxhmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.