Impact
A Stored Cross‑Site Scripting vulnerability exists in Frappe Framework 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer. The flaw allows an attacker to inject arbitrary HTML or JavaScript that will be executed in the victim’s browser when the breadcrumb is rendered, which is a classic input validation issue (CWE‑79).
Affected Systems
Affected systems include the Frappe Framework 17.0.0-dev across Linux, macOS, and Windows operating systems. Any instance running this developmental build is vulnerable.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate overall risk. No EPSS score is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers likely require the ability to submit a crafted breadcrumb entry via the web interface, which may be accessible to users who can view files. Once a malicious payload is inserted, it will be rendered in the victim’s browser when the breadcrumb is displayed.
OpenCVE Enrichment