Junglewise Threat Intelligence

CVE-2026-50701: Frappe Framework reflected XSS in dashboard-view breadcrumbs

CVE-2026-50701 · Severity: info · CVSS 5.1 · Published 2026-06-24

Vendors: Frappe.

Executive brief

Frappe Framework is a low-code web framework used to build business applications. A security vulnerability in its dashboard component allows attackers to execute malicious scripts in a user's browser if the user clicks a specially crafted link. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the dashboard-view component of Frappe Framework version 17.0.0-dev. The issue stems from improper neutralization of user-controlled input during the rendering of breadcrumbs in the dashboard view. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious URL containing a crafted payload. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser, potentially leading to session hijacking or unauthorized data access. The vulnerability is tracked as CWE-79.

Affected products

  • Frappe Frappe Framework 17.0.0-dev

Timeline

  • 2026-06-24: disclosed: Advisory published by Fluid Attacks and NVD

References