CVE-2025-30212: Frappe has possibility of SQL injection due to improper validations
Impact An SQL Injection vulnerability has been identified in Frappe Framework which could allow a malicious actor to access sensitive information.
Workarounds Upgrading is required, no other workaround is present.
Credits
Thanks to Thanh of Calif.io for reporting the issue
Other sources
Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework prior to versions 14.89.0 and 15.51.0 which could allow a malicious actor to access sensitive information. Versions 14.89.0 and 15.51.0 fix the issue. Upgrading is required; no other workaround is present.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/frappeto a version that resolves this vulnerability.Fixed in 15.51.0 - Upgrade
Upgrade
pip/frappeto a version that resolves this vulnerability.Fixed in 14.89.0 - Upgrade
Upgrade
Frappe Frameworkto a version that resolves this vulnerability.Fixed in 14.89.0 - Upgrade
Upgrade
Frappe Frameworkto a version that resolves this vulnerability.Fixed in 15.51.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30212?
CVE-2025-30212 is an SQL Injection vulnerability that poses a significant risk as it can allow malicious actors to access sensitive information.
How do I fix CVE-2025-30212?
To fix CVE-2025-30212, you must upgrade to Frappe Framework version 15.51.0 or 14.89.0.
What versions of Frappe Framework are affected by CVE-2025-30212?
CVE-2025-30212 affects Frappe Framework versions between 15.0.0 and 15.51.0, as well as versions up to 14.89.0.
Is there a workaround for CVE-2025-30212?
There are no workarounds available for CVE-2025-30212; upgrading is necessary to mitigate the risk.
Who reported the vulnerability CVE-2025-30212?
The vulnerability CVE-2025-30212 was reported by Thanh of Calif.io.