PT-2026-1347 · Frappé Technologies · Frappe

CVE-2025-68953

·

Publicado

2026-01-05

·

Atualizado

2026-01-06

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Frappe versions 14.99.5 and below and 15.0.0 through 15.80.1
Description Frappe, a full-stack web application framework, contains a path traversal issue in certain requests. Insufficient input sanitization allows the potential retrieval of arbitrary files from the server. The issue affects versions 14.99.5 and below, and versions 15.0.0 through 15.80.1.
Recommendations Update to Frappe version 14.99.6 or later. Update to Frappe version 15.88.1 or later. As a workaround, configure a reverse proxy.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-68953
GHSA-XJ39-3G4P-F46V

Produtos afetados

Frappe