Impact
The flaw arises from improper neutralization of user input in the desktop icon renderer, enabling a stored XSS payload to be executed when a user views the affected icon. This permits an attacker to run arbitrary JavaScript in the victim’s browser, potentially leading to cookie theft, session hijack, or further exploitation of the user’s environment. The vulnerability is classified as CWE‑79.
Affected Systems
The affected software is the Frappe Framework, version 17.0.0‑dev. The defect exists across all supported operating systems, including Linux, macOS, and Windows, as indicated by the CPE identifiers for each platform.
Risk and Exploitability
The CVSS score for this issue is 4.8, indicating moderate severity. No EPSS score is available, so the current estimate of exploitation likelihood is unclear. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation at the time of this report. Because the flaw is stored, an attacker would need to place malicious content into a desktop icon label, most likely through an authenticated interface or a user‑generated action within the Frappe application. Once the icon is rendered, the browser executes the malicious script, providing the attacker with the same privileges as the victim user.
OpenCVE Enrichment