ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 05 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Erpnext
Erpnext erpnext |
|
| Vendors & Products |
Erpnext
Erpnext erpnext |
Tue, 05 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Server‑Side Template Injection in ERPNext Email Templates | |
| Weaknesses | CWE-94 |
Tue, 05 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-05T16:08:31.506Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38431
No data.
Status : Received
Published: 2026-05-05T17:17:04.670
Modified: 2026-05-05T17:17:04.670
Link: CVE-2026-38431
No data.
OpenCVE Enrichment
Updated: 2026-05-05T20:00:12Z
Weaknesses