CVE-2025-67289
Critical · CVSS 9.6Frappe Framework — Arbitrary File Upload leading to Remote Code Execution (XSS/RCE via crafted XML)
- CVSS
- 9.6
- nvd
- EPSS
- 0.40%
- 32th pct
- KEV
- No
- Class
- oss containerizable
- CWE-79, CWE-434
Description
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
Search profile — drives PoC discovery
Symbols Attachmentsupload_filehandle_upload_responseallowed_extensionsxmlfrappe.utils.file_managersave_fileget_file_doc
Keywords CVE-2025-67289Frappe Framework arbitrary file uploadFrappe attachments XML upload RCEFrappe v15.89.0 file upload vulnerabilityFrappe CWE-434 XML upload exploitFrappe XSS file upload PoCvuquyen03 CVE-2025-67289
Versions: v15.89.0
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z