CVE-2025-67289
erpnext, frappe
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
- CVSS
- 9.6
- EPSS
- 0.39% 31.9% percentile
- CISA KEV
- Not listed
- Published
- 2025.12.23