CVE-2026-38431: Code Injection
ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-38431?
CVE-2026-38431 has a moderate severity rating due to its potential for server-side execution of injected template expressions.
How do I fix CVE-2026-38431?
To fix CVE-2026-38431, update ERPNext to version 15.103.2 or later, which addresses the server-side template injection vulnerability.
Who is affected by CVE-2026-38431?
CVE-2026-38431 affects users of ERPNext version 15.103.1 and earlier who have permissions to create or edit email templates.
What type of vulnerability is CVE-2026-38431?
CVE-2026-38431 is classified as a Server-Side Template Injection (SSTI) vulnerability.
What can attackers do with CVE-2026-38431?
Attackers can exploit CVE-2026-38431 to execute arbitrary code on the server by injecting template expressions into email templates.