Executive brief
Frappe Framework and ERPNext, which are used for building and managing business applications like ERP systems, are vulnerable to a security flaw in their file attachment feature. An attacker can upload a specially crafted file that, when opened by an administrator, allows the attacker to run malicious commands in the administrator's browser. This could lead to unauthorized access to sensitive business data, data modification, or full takeover of the administrative account.
Technical details
A stored Cross-Site Scripting (XSS) and unrestricted file upload vulnerability exists in the Attachments module of Frappe Framework and ERPNext v15.89.0. The root cause is a failure to sanitize or strip executable content (such as JavaScript) from uploaded .XML or .HTM files stored in the /private/files/ directory. An attacker can upload a malicious file and, through social engineering or administrative review, induce an administrator to access the direct file URL. Because the script executes within the context of the administrator's session, the attacker can achieve privilege escalation, data exfiltration, or unauthorized data manipulation. While the NVD description mentions arbitrary code execution, the technical proof-of-concept specifically details a stored XSS leading to session hijacking and administrative action.
Affected products
- Frappe Frappe Framework 15.89.0
- Frappe ERPNext 15.89.0
Timeline
- 2025-12-22: advisory: Initial CVE publication
- 2025-12-22: disclosed: Public disclosure of the vulnerability details