Server-Side Request Forgery (SSRF) in ERPNext - #VU142394
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to induce the server to send requests to unintended destinations and disclose limited information.
The vulnerability exists due to server-side request forgery in a configuration field for outbound requests when processing user-supplied destination values. A remote user can supply an arbitrary destination to cause the server to issue requests to hosts of their choosing and disclose limited information.
The destination may include addresses reachable only from inside the deployment's network.