VYPR
Critical severity9.8NVD Advisory· Published May 5, 2026· Updated May 8, 2026

CVE-2026-38431

CVE-2026-38431

Description

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.

Affected products

2
  • Frappe/Erpnextinferred2 versions
    <=15.103.1+ 1 more
    • (no CPE)range: <=15.103.1
    • cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*range: <=15.103.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.