CVE-2025-64707 Overview
CVE-2025-64707 affects Frappe Learning, a learning management system built on the Frappe framework. The vulnerability exists in versions starting at 2.0.0 and prior to 2.41.0. When administrators revoked a role from a user, the change did not take effect immediately because stale role data remained in cache. A user whose role was revoked could continue to exercise the privileges associated with that role until the cache expired or was manually cleared. The issue is classified under CWE-863 (Incorrect Authorization). Frappe addressed the flaw in version 2.41.0 by clearing the cache after role updates.
Critical Impact
Revoked users retain previously granted privileges until cached role data is cleared, creating a window of unauthorized access.
Affected Products
- Frappe Learning versions 2.0.0 through 2.40.x
- Deployments relying on administrative role revocation for access control
- Self-hosted and managed Frappe LMS instances exposed to authenticated users
Discovery Timeline
- 2025-11-12 - CVE-2025-64707 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-64707
Vulnerability Analysis
Frappe Learning caches user role assignments to reduce database lookups on authorization checks. The caching layer did not invalidate entries when an administrator removed a role from a user. Authorization decisions continued to reference the cached role set, granting access the administrator intended to revoke.
Exploitation requires high privileges on the target account because the attacker must already hold the role before revocation. The impact is limited to retaining existing privileges rather than acquiring new ones. The vulnerability does not expose confidentiality or availability but has a limited integrity impact because privileged actions continue after the administrative revocation.
Root Cause
The root cause is missing cache invalidation on role updates. The role-management workflow updated the authoritative role store but did not call the cache-clearing routine. Subsequent permission checks served stale authorization data, violating the principle that authorization state must reflect administrator intent in real time.
Attack Vector
The attack vector is network-based and requires an authenticated session with the role the administrator intends to revoke. After revocation, the affected user continues performing actions permitted by that role until the cache naturally expires or is manually flushed. There is no public proof of concept, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
Technical details are documented in the Frappe LMS GitHub Security Advisory GHSA-w2gf-rchw-x6vm.
Detection Methods for CVE-2025-64707
Indicators of Compromise
- Successful privileged actions performed by a user shortly after that user's role was revoked by an administrator
- Audit log entries showing role removal events followed by access to resources that should be gated by the revoked role
- Unexpected administrative or instructor-level operations originating from accounts recently downgraded to standard users
Detection Strategies
- Correlate role-change events in the Frappe audit log with subsequent authorization-sensitive API calls from the affected user ID
- Monitor the gap between administrative role revocation and the next successful privileged action by that account
- Review Redis or application cache contents for role entries that persist beyond expected invalidation points
Monitoring Recommendations
- Enable verbose logging on Frappe permission checks and role-update endpoints
- Alert on any privileged action performed within the cache time-to-live window after a role revocation
- Track application version strings to confirm deployment of Frappe Learning 2.41.0 or later
How to Mitigate CVE-2025-64707
Immediate Actions Required
- Upgrade Frappe Learning to version 2.41.0 or later, which clears the cache after role updates
- Manually flush the Frappe cache after any role revocation on unpatched instances using bench clear-cache
- Audit recent role revocations and verify affected users did not exercise retained privileges
Patch Information
The maintainers released a fix in Frappe Learning version 2.41.0. The patch ensures the role cache is invalidated whenever user roles are updated. Upgrade details are available in the GitHub Security Advisory GHSA-w2gf-rchw-x6vm.
Workarounds
- Run bench --site <site-name> clear-cache immediately after any administrative role change
- Force session termination for users whose roles are revoked so they must re-authenticate against fresh role data
- Restrict administrative role-management operations to a change-controlled process that includes cache invalidation
# Clear Frappe cache after role revocation on unpatched instances
bench --site your-site.local clear-cache
# Upgrade Frappe Learning to the fixed version
bench get-app --branch version-2.41.0 lms https://github.com/frappe/lms
bench --site your-site.local migrate
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.