Open Redirect Vulnerability in Frappe Framework
CVE-2025-62407
6.1MEDIUM
What is CVE-2025-62407?
The Frappe framework, a full-stack web application framework, contains a vulnerability that allows for open redirects via the redirect argument on the login page. This issue is triggered when a certain type of URL is provided to the redirect argument, which can potentially lead users to malicious websites unknowingly. The vulnerability has been addressed in the updates of versions 14.98.0 and 15.83.0.
Affected Version(s)
frappe >= 15.0.0, < 15.83.0 < 15.0.0, 15.83.0
frappe < 14.98.0 < 14.98.0