Cross-site scripting in ERPNext - #VU142408

 

Cross-site scripting in ERPNext - #VU142408

Published: August 13, 2026


Vulnerability identifier: #VU142408
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute script in the browser of an operator who opens the affected page.

The vulnerability exists due to cross-site scripting in record name rendering when processing item master data displayed on the affected page. A remote user can store a crafted record name to execute script in the browser of an operator who opens the affected page.

User interaction is required, and exploitation requires write access to item master data.


Affected software

ERPNext

Remediation

Install security update from vendor's website.

ERPNext - addressed in versions 15.110.0, 16.21.0

External References

Related Security Bulletins