CVE-2025-65267

CRITICAL

ERPNext v15.83.2 and Frappe Framework v15.86.0 - Stored Cross-Site Scripting via SVG Avatar Upload

Title source: llm
STIX 2.1

Description

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance.

Scores

CVSS v3 9.0
EPSS 0.0029
EPSS Percentile 20.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
frappe/erpnext 15.83.2
frappe/frappe 15.86.0
Published Dec 03, 2025
Tracked Since Feb 18, 2026