VYPR
Critical severity9.8NVD Advisory· Published May 5, 2026· Updated May 8, 2026

CVE-2026-38431

CVE-2026-38431

Description

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.

Affected products

2
  • Frappe/Erpnext2 versions
    cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*range: <=15.103.1
    • (no CPE)range: <=15.103.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.