CVE-2026-38431
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
05/05/2026
Last modified:
06/05/2026
Description
ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



