Improper Neutralization of Special Elements Used in a Template Engine in ERPNext - #VU142378
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in a template engine in user-controlled message fields when processing user-supplied message content. A remote user can inject crafted template expressions to execute arbitrary code.
Exploitation gives access to an unrestricted template context, which can enable arbitrary database reads and writes, document deletion, outbound requests from the server, and mail sent by the site.