CVE-2026-50699: Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule rendering
Published Jun 24, 2026
·Updated
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in referencedocument using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form.
Affected Software
1 affected component
Frappe Frappe Framework=17.0.0-dev
Event History
Jun 24, 2026
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-50699?
The severity of CVE-2026-50699 is rated at 43.
2
How do I fix CVE-2026-50699?
To fix CVE-2026-50699, upgrade to the latest stable version of the Frappe Framework that addresses this vulnerability.
3
What kind of vulnerability is CVE-2026-50699?
CVE-2026-50699 is a Stored Cross-Site Scripting (XSS) vulnerability.
4
Who can exploit CVE-2026-50699?
An authenticated attacker with write access to the Auto Repeat feature can exploit CVE-2026-50699.
5
What components of Frappe Framework are affected by CVE-2026-50699?
CVE-2026-50699 affects the Auto Repeat dashboard schedule rendering component of Frappe Framework.