Executive brief
Frappe Framework is a low-code web framework used to build business applications. A security vulnerability in its dashboard component allows attackers to execute malicious scripts in a user's browser if the user clicks a specially crafted link. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the dashboard-view component of Frappe Framework version 17.0.0-dev. The issue stems from improper neutralization of user-controlled input during the rendering of breadcrumbs in the dashboard view. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious URL containing a crafted payload. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser, potentially leading to session hijacking or unauthorized data access. The vulnerability is tracked as CWE-79.
Affected products
- Frappe Frappe Framework 17.0.0-dev
Timeline
- 2026-06-24: disclosed: Advisory published by Fluid Attacks and NVD