Access Vulnerability in Frappe Framework Affects User Password Security
CVE-2025-52898
8.7HIGH
What is CVE-2025-52898?
The Frappe Framework, a versatile web application development tool, has a vulnerability that could allow malicious actors to gain unauthorized access to a user's password reset token. This issue arises specifically in self-hosted environments that are configured improperly, while users on Frappe Cloud remain unaffected. This vulnerability is patched in versions 14.94.3 and 15.58.0, and users are advised to apply these updates or to validate password reset URLs before use to maintain security.
Affected Version(s)
frappe < 15.58.0 < 15.58.0
frappe < 14.94.3 < 14.94.3