Server-Side Request Forgery (SSRF) in ERPNext - #VU128503
Published: April 30, 2026
ERPNext
Detailed vulnerability description
The vulnerability allows a remote user to cause the server to make HTTP requests to services of the user's choice.
The vulnerability exists due to server-side request forgery (SSRF) in an endpoint when handling crafted requests. A remote user can send a crafted request to cause the server to make HTTP requests to services of the user's choice.