{"id":"CVE-2025-30213","aliases":["GHSA-v342-4xr9-x3q3","PYSEC-2026-1393"],"title":"Frappe has Possibility of Remote Code Execution due to improper validation","summary":"Frappe has Possibility of Remote Code Execution due to improper validation","severity":"medium","vendor":"frappe","product":"frappe","ecosystem":"pip","affected":["frappe < 14.91.0","frappe >= 15.0.0, < 15.52.0"],"patched":["frappe 14.91.0","frappe 15.52.0"],"published":"2025-03-25","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-v342-4xr9-x3q3","references":[{"url":"https://github.com/frappe/frappe/security/advisories/GHSA-v342-4xr9-x3q3"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30213"},{"url":"https://github.com/frappe/frappe"}],"tags":["osv","pip"],"epss":0.00709,"epssPercentile":0.52064,"ingestedAt":"2026-07-08T18:25:53.052Z","slug":"CVE-2025-30213","body":"## Overview\n\n### Impact\nA system user was able to create certain documents in a specific way that could lead to RCE.\n\n### Workarounds\nThere's no workaround, an upgrade is required.\n\n### Credits\nThanks to Thanh of Calif.io for reporting the issue\n\n## Affected packages\n\n- `frappe < 14.91.0`\n- `frappe >= 15.0.0, < 15.52.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `frappe 14.91.0`\n- `frappe 15.52.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}