← Vulnerability feed

Vulnerability record · CVE-2025-68953 · published 5 January 2026

CVE-2025-68953: Frappe path traversal vulnerability

Frappe · Frappe

Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path traversal attacks. Arbitrary files from the server could be retrieved due to a lack of proper sanitization on some requests. This issue is fixed in versions 14.99.6 and 15.88.1. To workaround, changing the setup to use a reverse proxy is recommended.

7.5 CVSS 3.1 High EPSS 0.42% · top 66.3% CWE-22 · Path traversal
7.5CVSS 3.1 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path traversal attacks. Arbitrary files from the server could be retrieved due to a lack of proper sanitization on some requests. This issue is fixed in versions 14.99.6 and 15.88.1. To workaround, changing the setup to use a reverse proxy is recommended.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-68953 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-66205Frappe sql injection vulnerabilityFrappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to…EPSS 0.31%9.8CVE-2019-14965Frappe code injection vulnerabilityAn issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.EPSS 2.6%9.6CVE-2025-67289Frappe erpnext cross-site scripting vulnerabilityAn arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploadin…EPSS 0.46%9.3CVE-2026-35614Frappe sql injection vulnerabilityFrappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update. This vulnerability is fix…EPSS 0.47%9.3CVE-2026-31877Frappe sql injection vulnerabilityFrappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result i…EPSS 0.47%9.1CVE-2026-31017Frappe erpnext server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where us…EPSS 0.42%9.0CVE-2025-68929Frappe vulnerabilityFrappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tri…EPSS 0.50%9.0CVE-2025-65267Frappe erpnext cross-site scripting vulnerabilityIn ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. …EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2025-68953), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.