CVE-2023-54345

Severity CVSS v4.0:
HIGH
Type:
CWE-94 Code Injection
Publication date:
05/05/2026
Last modified:
05/05/2026

Description

Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role to execute arbitrary code by exploiting frame introspection. Attackers can create a server script via the /app/server-script endpoint and access the gi_frame attribute to traverse the call stack and invoke os.popen to execute system commands.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:frappe:erpnext:13.4.0:*:*:*:*:*:*:*