Junglewise Threat Intelligence

CVE-2026-50698: Frappe Framework stored XSS in Audit Trail

CVE-2026-50698 · Severity: info · CVSS 4.6 · Published 2026-06-24

Technologies: Frappe Technologies Frappe Framework. Vendors: Frappe Technologies, Frappe.

Executive brief

Frappe Framework, a low-code web framework used for building business applications, is vulnerable to a security flaw in its Audit Trail component. An attacker with high-level administrative privileges can inject malicious scripts into the system that will execute when other users view the audit logs. This could lead to unauthorized actions being performed in the context of the victim's session or the theft of sensitive information displayed in the management interface.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Frappe Framework version 17.0.0-dev. The flaw is located within the Audit Trail component, where user-controlled input is improperly neutralized before being rendered as HTML output in templates. An attacker with high privileges (PR:H) can exploit this by injecting malicious JavaScript that is stored on the server. The payload executes when an authorized user interacts with the affected Audit Trail page. According to the CVSS 4.0 score provided by the CNA, the impact is limited to a low-integrity and low-confidentiality breach of the subsequent system (SC:L/SI:L).

Affected products

  • Frappe Frappe Framework 17.0.0-dev

Timeline

  • 2026-06-24: disclosed: Advisory published by Fluid Attacks and NVD

References

Related threats