CVE-2026-38431: Frappe Erpnext

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.

Affected products

  • Frappe Erpnext: up to and including 15.103.1

Published 2026-05-05. Last modified 2026-07-24.