CVE-2026-38431
erpnext
ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
- CVSS
- 9.8
- EPSS
- 0.39% 31.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.06