Access Vulnerability in Frappe Framework Affects User Password Security
CVE-2025-52898

8.7HIGH

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
30 June 2025

What is CVE-2025-52898?

The Frappe Framework, a versatile web application development tool, has a vulnerability that could allow malicious actors to gain unauthorized access to a user's password reset token. This issue arises specifically in self-hosted environments that are configured improperly, while users on Frappe Cloud remain unaffected. This vulnerability is patched in versions 14.94.3 and 15.58.0, and users are advised to apply these updates or to validate password reset URLs before use to maintain security.

Affected Version(s)

frappe < 15.58.0 < 15.58.0

frappe < 14.94.3 < 14.94.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52898 : Access Vulnerability in Frappe Framework Affects User Password Security