Junglewise Threat Intelligence

CVE-2026-50708: Frappe Framework stored XSS in MultiSelectDialog

CVE-2026-50708 · Severity: info · CVSS 4.8 · Published 2026-06-24

Vendors: Frappe.

Executive brief

Frappe Framework, a low-code web framework used for building business applications, is vulnerable to a security flaw in its multi-select dialog component. An attacker with basic user privileges can inject malicious scripts that execute in the browsers of other users. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in the MultiSelectDialog component of Frappe Framework version 17.0.0-dev. The vulnerability stems from improper neutralization of user-controlled input during the rendering of results within the dialog. An authenticated attacker with low privileges can inject malicious JavaScript that is stored on the server and subsequently executed in the context of another user's browser session when they interact with the affected component. This requires some user interaction (UI:A) to trigger the payload. At the time of the advisory, the vulnerability was identified in the development branch (17.0.0-dev).

Affected products

  • Frappe Frappe Framework 17.0.0-dev

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory

References