Improper Neutralization of Special Elements Used in a Template Engine in ERPNext - CVE-2026-55242
Published: July 7, 2026
ERPNext
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper neutralization of special elements used in a template engine in a configuration field when processing user-supplied template input. A local user can inject a crafted template expression to disclose sensitive information.
The disclosed data may be outside the user's normal permission scope.