ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
Metrics
Affected Vendors & Products
References
History
Fri, 08 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe erpnext |
|
| CPEs | cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Frappe
Frappe erpnext |
Wed, 06 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Server‑Side Template Injection in ERPNext Email Templates |
Wed, 06 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 05 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Erpnext
Erpnext erpnext |
|
| Vendors & Products |
Erpnext
Erpnext erpnext |
Tue, 05 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Server‑Side Template Injection in ERPNext Email Templates | |
| Weaknesses | CWE-94 |
Tue, 05 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-05-05T00:00:00.000Z
Updated: 2026-05-06T15:26:19.751Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38431
Updated: 2026-05-06T13:51:20.397Z
Status : Analyzed
Published: 2026-05-05T17:17:04.670
Modified: 2026-05-08T17:06:43.360
Link: CVE-2026-38431
No data.