{"id":"CVE-2025-30214","aliases":["GHSA-qrv3-jc3h-f3m6","PYSEC-2026-1392"],"title":"Frappe vulnerable to information disclosure leading to account takeover","summary":"Frappe vulnerable to information disclosure leading to account takeover","severity":"high","vendor":"frappe","product":"frappe","ecosystem":"pip","affected":["frappe < 14.89.0","frappe >= 15.0.0, < 15.51.0"],"patched":["frappe 14.89.0","frappe 15.51.0"],"published":"2025-03-25","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-qrv3-jc3h-f3m6","references":[{"url":"https://github.com/frappe/frappe/security/advisories/GHSA-qrv3-jc3h-f3m6"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30214"},{"url":"https://github.com/frappe/frappe"}],"tags":["osv","pip"],"epss":0.004,"epssPercentile":0.31411,"ingestedAt":"2026-07-08T18:25:52.486Z","slug":"CVE-2025-30214","body":"## Overview\n\n### Impact\nMaking crafted requests could lead to information disclosure that could further lead to account takeover.\n\n### Workarounds\nThere's no workaround to fix this without upgrading.\n\n### Credits\nThanks to Thanh of Calif.io for reporting the issue\n\n## Affected packages\n\n- `frappe < 14.89.0`\n- `frappe >= 15.0.0, < 15.51.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `frappe 14.89.0`\n- `frappe 15.51.0`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}