XML External Entity injection in ERPNext - #VU128501
Published: April 30, 2026
ERPNext
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper restriction of xml external entity reference in the EDI Module when processing XML documents. A remote user can supply a crafted XML document to disclose sensitive information.
The issue can expose files from the local file system, including sensitive configuration files.