ZeroHour

CVE-2026-38431

PoC
CVSS 3.1
9.8 critical
EPSS
<1%p33
Published
()
Modified
Description

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.

Vendors
frappe
Products
erpnext
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.