ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
References
| Link | Resource |
|---|---|
| https://c0wking.hashnode.dev/ssti-in-erpnext-frappe-email-template-engine | Exploit Third Party Advisory |
| https://c0wking.hashnode.dev/ssti-in-erpnext-frappe-email-template-engine | Exploit Third Party Advisory |
Configurations
History
08 May 2026, 17:06
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:* | |
| References | () https://c0wking.hashnode.dev/ssti-in-erpnext-frappe-email-template-engine - Exploit, Third Party Advisory | |
| First Time |
Frappe
Frappe erpnext |
06 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-94 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://c0wking.hashnode.dev/ssti-in-erpnext-frappe-email-template-engine - |
05 May 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-05 17:17
Updated : 2026-05-08 17:06
NVD link : CVE-2026-38431
Mitre link : CVE-2026-38431
CVE.ORG link : CVE-2026-38431
JSON object : View
Products Affected
frappe
- erpnext
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
