Cross-site scripting in ERPNext - #VU151524
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote user to execute script in the session of a user who opens a report.
The vulnerability exists due to improper neutralization of input during web page generation in the report view when rendering stored record names in markup. A remote user can create a record with a crafted name to execute script in the session of a user who opens a report.
User interaction is required to open the report.