CVE-2025-30213: Frappe has Possibility of Remote Code Execution due to improper validation
Impact A system user was able to create certain documents in a specific way that could lead to RCE.
Workarounds There's no workaround, an upgrade is required.
Credits Thanks to Thanh of Calif.io for reporting the issue
Other sources
Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a specific way that could lead to remote code execution. Versions 14.9.1 and 15.52.0 contain a patch for the vulnerability. There's no workaround; an upgrade is required.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/frappeto a version that resolves this vulnerability.Fixed in 15.52.0 - Upgrade
Upgrade
pip/frappeto a version that resolves this vulnerability.Fixed in 14.91.0 - Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 14.9.1 - Upgrade
Upgrade
Frappeto a version that resolves this vulnerability.Fixed in 15.52.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30213?
CVE-2025-30213 has a high severity level due to its potential for remote code execution.
How do I fix CVE-2025-30213?
To fix CVE-2025-30213, you need to upgrade to either version 15.52.0 or 14.91.0 of the Frappe framework.
What kind of attack does CVE-2025-30213 facilitate?
CVE-2025-30213 facilitates remote code execution if exploited by an attacker.
Which versions of Frappe are affected by CVE-2025-30213?
CVE-2025-30213 affects Frappe versions between 15.0.0 and 15.52.0, as well as all versions prior to 14.91.0.
Is there a workaround for CVE-2025-30213?
There are no workarounds for CVE-2025-30213; an upgrade is mandatory.