ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
Metrics
Affected Vendors & Products
References
History
Tue, 05 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Erpnext
Erpnext erpnext |
|
| Vendors & Products |
Erpnext
Erpnext erpnext |
Tue, 05 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Server‑Side Template Injection in ERPNext Email Templates | |
| Weaknesses | CWE-94 |
Tue, 05 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-05T16:08:31.506Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38431
No data.
Status : Received
Published: 2026-05-05T17:17:04.670
Modified: 2026-05-05T17:17:04.670
Link: CVE-2026-38431
No data.
OpenCVE Enrichment
Updated: 2026-05-05T20:00:12Z