Junglewise Threat Intelligence

CVE-2026-44205: Frappe Framework stored XSS in user profile image section

CVE-2026-44205 · Severity: info · CVSS 6.9 · Published 2026-06-12

Vendors: Frappe.

Executive brief

Frappe is a web application framework used to build business software. A security flaw in the user profile section allows an attacker to upload a malicious image file that contains hidden scripts. When other users view the attacker's profile, these scripts execute in their browser, potentially allowing the attacker to perform unauthorized actions or steal session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Frappe Framework prior to version 15.106.0. The flaw is located in the user profile image upload component, where insufficient input validation or output encoding allows for the injection of malicious scripts. An attacker can exploit this by uploading a specially crafted file that, when rendered by the application, executes JavaScript in the context of other users' sessions. This is a network-reachable vulnerability that does not require specific user interaction beyond viewing the profile. The issue has been addressed in version 15.106.0.

Affected products

  • Frappe Frappe Framework < 15.106.0

Timeline

  • 2026-05-27: advisory: GitHub security advisory published by maintainer
  • 2026-06-12: disclosed: CVE published to NVD dataset

References