Improper Neutralization of Special Elements Used in a Template Engine in ERPNext - CVE-2026-65974
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the server.
The vulnerability exists due to improper neutralization of special elements used in a template engine in the template engine when processing crafted template input through a permission boundary bypass. A remote user can inject a crafted template payload to execute arbitrary code on the server.
The issue can be exploited by an authenticated user with limited privileges.