๐Ÿ” CVE Alert

CVE-2026-50699

UNKNOWN 0.0

Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule rendering

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form.

CWE CWE-79
Vendor frappe
Product frappe framework
Published Jun 24, 2026
Last Updated Jun 24, 2026
Stay Ahead of the Next One

Get instant alerts for frappe frappe framework

Be the first to know when new unknown vulnerabilities affecting frappe frappe framework are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Frappe / Frappe Framework
17.0.0-dev

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
fluidattacks.com: https://fluidattacks.com/es/advisories/monkeys github.com: https://github.com/frappe/frappe

Credits

Fluid Attacks' AI SAST Scanner Oscar Uribe