Loading
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
Cite this page
CVE-2025-67289. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-67289
Use CWE-79, Frappe vendor hub and Erpnext product page to widen CVE-2025-67289 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-27471, CVE-2026-31017 and CVE-2025-66440 for nearby disclosures in the same product family.