Arbitrary File Upload Risk in Frappe Framework Attachments Module
CVE-2025-67289
9.6CRITICAL
What is CVE-2025-67289?
An arbitrary file upload vulnerability exists within the Attachments module of the Frappe Framework version 15.89.0. This flaw permits attackers to upload crafted XML files, potentially leading to the execution of arbitrary code on the host system. Proper validation mechanisms must be put in place to mitigate this risk and safeguard sensitive information against unauthorized access and exploitation.
