CVE-2026-38431 PUBLISHED

Assigner: mitre
Reserved: 06.04.2026 Published: 05.05.2026 Updated: 05.05.2026

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.

Product Status

Vendor n/a
Product n/a
Versions
  • Version n/a is affected

References

Problem Types

  • n/a text