Cross-site scripting in ERPNext - #VU142397
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to execute script in the browser of another user.
The vulnerability exists due to cross-site scripting in the record name field when rendering a record name without escaping. A remote user can edit a record name with crafted script content to execute script in the browser of another user.
User interaction is required when a colleague opens the affected page.