CVE-2026-38431Disclosure(frappe / erpnext)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch frappe erpnext systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • erpnext

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-05-12); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
erpnext

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-05-12: 4Mentions · 2026-05-25: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-12: 3Technical Details · 2026-05-25: 105-1205-25
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-124
Disclosure3General1
2026-05-251
Patch1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-38431 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The Lyrie pipeline confirms CVE-2026-38431 as a critical vulnerability with CVSS 9.8, but no PoC, exploit, or patch information is provided.

    1000037
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-38431 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI).

    Post summary

    An advisory announces a critical Server‑Side Template Injection vulnerability (CVE‑2026‑38431) in ERPNext v15.103.1 and earlier, assigning a CVSS 9.8 score.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-38431 (CVSS 9.8) — multiple products. CVE: CVE-2026-38431 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    A critical vulnerability (CVE-2026-38431) with CVSS 9.8 is announced, but no PoC, exploit, or patch information is included.

    1000030
    210 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-38431 (CVSS 9.8) ERPNext v15.103.1 & prior vulnerable to Server-Side Template Injection (SSTI). Attackers can inject malicious template expressions via email templates. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/kWiQn6uFkR

    Post summary

    An alert for a critical SSTI vulnerability in ERPNext v15.103.1 and earlier versions, urging immediate patching to mitigate the CVE-2026-38431 risk.

    0000054
    30 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-38431-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post merely contains a URL and generic hashtags, offering no concrete details about the CVE, so the content is classified as general with low confidence.

    0000024
    210 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrappeerpnext---

Explore more