CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-38431

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-94

Description

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.

References

Status: profiled · ingested 2026-07-25T00:00:18.000Z