Improper Neutralization of Special Elements Used in a Template Engine in ERPNext - #VU142378

 

Improper Neutralization of Special Elements Used in a Template Engine in ERPNext - #VU142378

Published: August 13, 2026


Vulnerability identifier: #VU142378
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-1336
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements used in a template engine in user-controlled message fields when processing user-supplied message content. A remote user can inject crafted template expressions to execute arbitrary code.

Exploitation gives access to an unrestricted template context, which can enable arbitrary database reads and writes, document deletion, outbound requests from the server, and mail sent by the site.


Affected software

ERPNext

Remediation

Install security update from vendor's website.

ERPNext - addressed in versions 15.119.1, 16.32.0

External References

Related Security Bulletins