CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-67289

Critical · CVSS 9.6

Frappe Framework — Arbitrary File Upload leading to Remote Code Execution (XSS/RCE via crafted XML)

CVSS
9.6
nvd
EPSS
0.40%
32th pct
KEV
No
Class
oss containerizable
CWE-79, CWE-434

Description

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

Search profile — drives PoC discovery

Symbols Attachmentsupload_filehandle_upload_responseallowed_extensionsxmlfrappe.utils.file_managersave_fileget_file_doc
Keywords CVE-2025-67289Frappe Framework arbitrary file uploadFrappe attachments XML upload RCEFrappe v15.89.0 file upload vulnerabilityFrappe CWE-434 XML upload exploitFrappe XSS file upload PoCvuquyen03 CVE-2025-67289
Versions: v15.89.0

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z