ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
History

Fri, 08 May 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Frappe
Frappe erpnext
CPEs cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:*
Vendors & Products Frappe
Frappe erpnext

Wed, 06 May 2026 18:15:00 +0000

Type Values Removed Values Added
Title Server‑Side Template Injection in ERPNext Email Templates

Wed, 06 May 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 05 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Erpnext
Erpnext erpnext
Vendors & Products Erpnext
Erpnext erpnext

Tue, 05 May 2026 19:15:00 +0000

Type Values Removed Values Added
Title Server‑Side Template Injection in ERPNext Email Templates
Weaknesses CWE-94

Tue, 05 May 2026 17:00:00 +0000

Type Values Removed Values Added
Description ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-05-05T00:00:00.000Z

Updated: 2026-05-06T15:26:19.751Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38431

cve-icon Vulnrichment

Updated: 2026-05-06T13:51:20.397Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-05T17:17:04.670

Modified: 2026-05-08T17:06:43.360

Link: CVE-2026-38431

cve-icon Redhat

No data.