Junglewise Threat Intelligence

CVE-2026-50704: Frappe Framework Stored XSS in File View breadcrumb renderer

CVE-2026-50704 · Severity: info · CVSS 4.6 · Published 2026-06-24

Vendors: Frappe.

Executive brief

A security vulnerability exists in the Frappe Framework, a popular web development platform. An attacker with high-level privileges can inject malicious scripts into the file navigation interface. If another user views these files, the script could execute in their browser, potentially leading to unauthorized actions or data access within the application.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability was identified in Frappe Framework version 17.0.0-dev. The flaw resides in the File View breadcrumb renderer, which fails to properly neutralize user-supplied input before rendering it in the web interface. An attacker with high privileges (PR:H) can exploit this by uploading or naming files/folders with malicious payloads. When an administrative user interacts with the affected breadcrumb navigation, the script executes in their session context. This can lead to session hijacking or unauthorized configuration changes. The vulnerability is tracked as CVE-2026-50704.

Affected products

  • Frappe Frappe Framework 17.0.0-dev

Timeline

  • 2026-06-24: disclosed: Advisory published by Fluid Attacks and NVD

References