CVE-2026-65974
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Summary
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals, allowing server-side template injection and remote code execution. This issue is fixed in versions 15.111.0 and 16.22.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| frappe | erpnext | < 15.111.0 | affected |
| frappe | erpnext | >= 16.0.0, < 16.22.0 | affected |
Weaknesses
- CWE-1336: CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
References
- https://github.com/frappe/erpnext/security/advisories/GHSA-w996-r7v3-87wr
- https://github.com/frappe/frappe/commit/529d190a252863672164d10bfcd91d1de0ac1c7c
- https://github.com/frappe/erpnext/releases/tag/v15.111.0
- https://github.com/frappe/erpnext/releases/tag/v16.22.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.