Cross-site scripting in ERPNext - #VU142408
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to execute script in the browser of an operator who opens the affected page.
The vulnerability exists due to cross-site scripting in record name rendering when processing item master data displayed on the affected page. A remote user can store a crafted record name to execute script in the browser of an operator who opens the affected page.
User interaction is required, and exploitation requires write access to item master data.