Frappe

Frappe

Top 100K site
VDPActive Recognition

Program Details

Report security vulnerabilities in ERPNext and Frappe Cloud by email to [email protected]. Include a description of the issue, supporting technical details and steps to reproduce, any disclosure plans, and whether you want public recognition. Only test accounts you own may be used, and accessing or modifying other users' data is prohibited. Frappe asks for 10-15 days to confirm and respond, and for blind XSS testing to use assets you control rather than third-party sites.

Rules & Testing

Excluded Methods

DosSocial EngineeringPhishingPhysical Access

In-Scope Domains

  • *.erpnext.com
  • *.frappecloud.com

Out of Scope

build.erpnext.com, gateway.erpnext.com, erpnext.atlassian.net, discuss.erpnext.com, GitHub wikis, Credential or info leak in test files

Security

Preferred Languages
English

security.txt

Contact
mailto:[email protected], https://security.frappe.io
Policy
https://frappe.io/security
Languages
en
Expires
Dec 31, 2026
View raw security.txt →