CVE-2025-65924Disclosure(frappe / erpnext)

LOWCVSS 4.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are intended for plain text. Although JavaScript is blocked (preventing XSS), the HTML is still preserved in the generated PDF document. As a result, an attacker can inject malicious clickable links into an ERP-generated PDF. Since PDF files generated by the ERP system are generally considered trustworthy, users are highly likely to click these links, potentially enabling phishing attacks or malware delivery. This issue occurs in the Add Quality Goal' function.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-80

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • erpnext

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
erpnext

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-03: 1Technical Details · 2026-02-03: 102-03
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2025-65924 ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `&lt;a&gt;` hyperlinks in fields that are intended for plain text. Although JavaScript is bl… https://www.cve.org/CVERecord?id=CVE-2025-65924

    Post summary

    ERPNext versions up to 15.88.1 do not sanitize <a> tags in plain‑text fields, exposing a potential XSS vulnerability.

    00000146
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrappeerpnext---

Explore more