CVE-2026-31017Disclosure(frappe / erpnext)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs from user-controlled HTML content, the application allows the inclusion of HTML elements such as <iframe> that reference external resources. The PDF rendering engine automatically fetches these resources on the server side. An attacker can abuse this behavior to force the server to make arbitrary HTTP requests to internal services, including cloud metadata endpoints, potentially leading to sensitive information disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • erpnext
  • frappe

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-13)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
erpnextfrappe

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-08: 1Mentions · 2026-04-13: 2Technical Details · 2026-04-08: 1Technical Details · 2026-04-13: 204-0804-13
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-081
Disclosure1
2026-04-132
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-31017 A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML … https://www.cve.org/CVERecord?id=CVE-2026-31017

    Post summary

    The post announces a Server‑Side Request Forgery vulnerability in ERPNext and Frappe, detailing the affected versions but lacking PoC, exploit code, or patch information.

    00010273
    57.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31017 A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML … https://www.cve.org/CVERecord?id=CVE-2026-31017 ----- Traducción: Existe una vulnera… http://infoflow.cloud`

    Post summary

    CVE-2026-31017 is a Server‑Side Request Forgery vulnerability affecting ERPNext v16.0.1 and Frappe Framework v16.1.1’s Print Format functionality, with no PoC, exploit code, or patch information provided in the announcement.

    0000039
    71 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31017 Server-Side Request Forgery in ERPNext v16.0.1 Print Format PDF Rendering https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31017

    Post summary

    The post announces CVE-2026-31017, describing a Server‑Side Request Forgery in ERPNext v16.0.1's PDF rendering, but provides no PoC, exploit, or mitigation details.

    0000076
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appfrappeerpnext16.0.1--
Appfrappefrappe16.1.1--

Explore more