CVE-2026-25956: Frappe Affected by XSS and Open Redirect in Sign Up
Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site which could lead to an open redirect (or reflected XSS, depending on the crafted payload) when a user signs up. This vulnerability is fixed in 14.99.14 and 15.94.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25956?
CVE-2026-25956 is classified as a medium severity vulnerability due to the potential for XSS and open redirect attacks.
How do I fix CVE-2026-25956?
To fix CVE-2026-25956, update your Frappe installation to version 14.99.14 or 15.94.0 or later.
What are the potential impacts of CVE-2026-25956?
The potential impacts of CVE-2026-25956 include unauthorized access and the ability for attackers to execute malicious scripts in the context of affected users.
Which versions of Frappe are affected by CVE-2026-25956?
Frappe versions prior to 14.99.14 and 15.94.0 are affected by CVE-2026-25956.
Is CVE-2026-25956 being actively exploited?
As of now, there is no public indication that CVE-2026-25956 is being actively exploited, but it is recommended to patch your systems promptly.