CVE-2026-38431

CRITICAL

ERPNext <= 15.103.1 - Server-Side Template Injection

Title source: manual
STIX 2.1

Description

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.

Scores

CVSS v3 9.8
EPSS 0.0039
EPSS Percentile 30.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
frappe/erpnext < 15.103.1
Published May 05, 2026
Tracked Since May 05, 2026