Path Traversal Vulnerability in Frappe Framework Affecting Multiple Versions
CVE-2025-66206
What is CVE-2025-66206?
The Frappe Framework prior to versions 15.86.0 and 14.99.2 is susceptible to path traversal attacks. This vulnerability allows attackers to access sensitive files from the server if they possess knowledge of the file path. Users hosting applications on Frappe Cloud and setups behind reverse proxies, such as NGINX, are not affected. However, those directly using werkzeug/gunicorn are at risk. It is highly recommended to upgrade to the latest versions or implement a reverse proxy configuration to mitigate potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
frappe >= 15.0.0, < 15.86.0 < 15.0.0, 15.86.0
frappe < 14.99.2 < 14.99.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
