PT-2026-37088 · Frappe · Erpnext
C0Wking
·
Published
2026-05-05
·
Updated
2026-05-25
·
CVE-2026-38431
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ERPNext versions prior to 15.103.2
Description
Server-Side Template Injection (SSTI) occurs when an attacker with permissions to create or edit email templates injects template expressions. These expressions are executed on the server during the template rendering process.
Recommendations
Update to a version later than 15.103.1.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Erpnext