Server-Side Request Forgery (SSRF) in ERPNext - #VU142394

 

Server-Side Request Forgery (SSRF) in ERPNext - #VU142394

Published: August 13, 2026


Vulnerability identifier: #VU142394
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to induce the server to send requests to unintended destinations and disclose limited information.

The vulnerability exists due to server-side request forgery in a configuration field for outbound requests when processing user-supplied destination values. A remote user can supply an arbitrary destination to cause the server to issue requests to hosts of their choosing and disclose limited information.

The destination may include addresses reachable only from inside the deployment's network.


Affected software

ERPNext

Remediation

Install security update from vendor's website.

ERPNext - addressed in versions 15.112.0, 16.23.0

External References

Related Security Bulletins