XML External Entity injection in ERPNext - CVE-2026-44445
Published: April 30, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper restriction of xml external entity reference in the EDI Module when processing XML documents. A remote user can supply a crafted XML document to disclose sensitive information.
The issue can expose files from the local file system, including sensitive configuration files.