GHSA-rv4r-c8v3-3hrc GHSA-v38v-9h2p-hr8v GHSA-734c-hv9r-mg2c GHSA-f99r-gp2w-xghj GHSA-cgjf-xw8x-qjjc GHSA-vr45-2p9x-3vjc GHSA-wp9w-rxmg-6pfj GHSA-wwgm-3pv3-gmqh GHSA-5wpj-6rvp-9ff7 GHSA-726x-68g4-fj9v
ERPNext 15 and 16 fix critical account takeover, SQL injection and authorisation flaws
Frappe has fixed critical and high-severity flaws in ERPNext, including unauthenticated stored XSS account takeover and SQL injection by any authenticated user. No workaround exists. Upgrade 15.x to 15.121.3 and 16.x to 16.35.0.
What happened
Frappe's ERPNext advisory bundle erpnext-2026-W38 covers ten security advisories. The most severe are two critical flaws. GHSA-rv4r-c8v3-3hrc is a stored cross-site scripting issue in content submitted through a public-facing booking page. Because the input was stored without neutralisation and later rendered as raw HTML in a privileged user's session, an unauthenticated attacker could execute script in that session and act as that user.
GHSA-v38v-9h2p-hr8v is a SQL injection issue caused by missing validation in some endpoints. A specially crafted request allowed any authenticated user, including one with no assigned roles, to read sensitive information belonging to other users and to escalate to a privileged account. Both flaws are rated critical with CVSS scores of 9.3 and 9.6.
The remaining eight advisories are high severity: stored cross-site scripting in tool and report views, and several missing authorization checks that allow unauthorised record creation, modification, status changes, and read access to party or financial data. Frappe states no workaround is available for any of these; upgrading is required. The advisories do not report active exploitation.
Who is affected
All ERPNext 15 versions before 15.121.3 and all ERPNext 16 versions before 16.35.0 are affected by at least one of these advisories. The first stored cross-site scripting flaw is fixed in 15.119.1 and 16.32.0, but those releases do not include the later authorisation fixes. ERPNext users should treat the 15.121.3 and 16.35.0 releases as the safe target for the whole bundle.
What to do now
- Apply the latest fixed release: upgrade ERPNext 15.x to at least 15.121.3, and ERPNext 16.x to at least 16.35.0. These are the latest fixed versions listed in the bundle.
- If you cannot upgrade immediately, prioritise the public-facing booking page and any ERPNext instance reachable from the internet. Frappe has not published a workaround for any of these flaws.
- Restrict network exposure of your ERPNext instance while planning the upgrade, and review privileged accounts for unexpected activity.
- Re-run integration and customisation tests after upgrading, then confirm the upgrade is complete.
How to detect it
Frappe's advisories do not include indicators of compromise. While preparing to upgrade, review ERPNext access logs for unexpected privileged actions, records read or changed by users without corresponding roles, and anonymous submissions to the public booking page that were later opened in a privileged session.
Beyond the patch
This bundle shows why exposure and access control should be treated as one problem: the worst flaw is unauthenticated, while the rest require only a low-privileged account. Our Virtual CISO Services (vCISO) helps identify ERPNext instances and other services reachable from the network, and an Implementation & Assessment Services penetration test and hardening review can validate that authorisation checks hold for your actual configuration and customisations.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| GHSA-rv4r-c8v3-3hrc ERPNext | – < 15.119.1 – < 16.32.0 | 15.119.1 16.32.0 1, 16.32.0 |
| GHSA-v38v-9h2p-hr8v, GHSA-vr45-2p9x-3vjc, GHSA-wp9w-rxmg-6pfj, GHSA-5wpj-6rvp-9ff7 ERPNext | – < 15.121.0 – < 16.34.0 | 15.121.0 16.34.0 0, 16.34.0 |
| GHSA-734c-hv9r-mg2c ERPNext | – < 15.112.0 – < 16.23.0 | 15.112.0 16.23.0 0, 16.23.0 |
| GHSA-f99r-gp2w-xghj ERPNext | – < 15.120.0 – < 16.33.0 | 15.120.0 16.33.0 0, 16.33.0 |
| GHSA-cgjf-xw8x-qjjc, GHSA-726x-68g4-fj9v ERPNext | – < 15.121.3 – < 16.35.0 | 15.121.3 16.35.0 3, 16.35.0 |
| GHSA-wwgm-3pv3-gmqh ERPNext | – < 15.120.0 – < 16.23.0 | 15.120.0 16.23.0 0, 16.23.0 |
References
Vendor advisory
- Account takeover via stored cross-site scripting
- Possibility of SQL injection due to missing validation
- Stored cross-site scripting due to missing validation
- Stored cross-site scripting due to missing validation
- Unauthorised modification of data due to missing validation
- Unauthorised record creation due to missing validation
- Unauthorised status modification due to missing validation
- Unauthorised access to party records due to missing validation