CVE-2025-55006 MEDIUM

CVE-2025-55006: Frappe Learning Holds Potential for Malicious SVG Upload in Image Upload Feature

Vendor Frappe
Product lms
Weakness CWE-20 · Input validation
Published August 9, 2025
Last update August 11, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately sanitize uploaded SVG files. This allowed users to upload SVG files containing embedded JavaScript or other potentially malicious content. Malicious SVG files could be used to execute arbitrary scripts in the context of other users. A fix for this issue is planned for version 2.34.0.

Key dates

02Disclosure timeline

August 9, 2025 CVE published
August 11, 2025 Record updated