Skip to content

GHSA-rv4r-c8v3-3hrc GHSA-v38v-9h2p-hr8v GHSA-734c-hv9r-mg2c GHSA-f99r-gp2w-xghj GHSA-cgjf-xw8x-qjjc GHSA-vr45-2p9x-3vjc GHSA-wp9w-rxmg-6pfj GHSA-wwgm-3pv3-gmqh GHSA-5wpj-6rvp-9ff7 GHSA-726x-68g4-fj9v

ERPNext 15 and 16 fix critical account takeover, SQL injection and authorisation flaws

Critical 9.6 Vendor: Frappe / ERPNext Published

Frappe has fixed critical and high-severity flaws in ERPNext, including unauthenticated stored XSS account takeover and SQL injection by any authenticated user. No workaround exists. Upgrade 15.x to 15.121.3 and 16.x to 16.35.0.

What happened

Frappe's ERPNext advisory bundle erpnext-2026-W38 covers ten security advisories. The most severe are two critical flaws. GHSA-rv4r-c8v3-3hrc is a stored cross-site scripting issue in content submitted through a public-facing booking page. Because the input was stored without neutralisation and later rendered as raw HTML in a privileged user's session, an unauthenticated attacker could execute script in that session and act as that user.

GHSA-v38v-9h2p-hr8v is a SQL injection issue caused by missing validation in some endpoints. A specially crafted request allowed any authenticated user, including one with no assigned roles, to read sensitive information belonging to other users and to escalate to a privileged account. Both flaws are rated critical with CVSS scores of 9.3 and 9.6.

The remaining eight advisories are high severity: stored cross-site scripting in tool and report views, and several missing authorization checks that allow unauthorised record creation, modification, status changes, and read access to party or financial data. Frappe states no workaround is available for any of these; upgrading is required. The advisories do not report active exploitation.

Who is affected

All ERPNext 15 versions before 15.121.3 and all ERPNext 16 versions before 16.35.0 are affected by at least one of these advisories. The first stored cross-site scripting flaw is fixed in 15.119.1 and 16.32.0, but those releases do not include the later authorisation fixes. ERPNext users should treat the 15.121.3 and 16.35.0 releases as the safe target for the whole bundle.

What to do now

  1. Apply the latest fixed release: upgrade ERPNext 15.x to at least 15.121.3, and ERPNext 16.x to at least 16.35.0. These are the latest fixed versions listed in the bundle.
  2. If you cannot upgrade immediately, prioritise the public-facing booking page and any ERPNext instance reachable from the internet. Frappe has not published a workaround for any of these flaws.
  3. Restrict network exposure of your ERPNext instance while planning the upgrade, and review privileged accounts for unexpected activity.
  4. Re-run integration and customisation tests after upgrading, then confirm the upgrade is complete.

How to detect it

Frappe's advisories do not include indicators of compromise. While preparing to upgrade, review ERPNext access logs for unexpected privileged actions, records read or changed by users without corresponding roles, and anonymous submissions to the public booking page that were later opened in a privileged session.

Beyond the patch

This bundle shows why exposure and access control should be treated as one problem: the worst flaw is unauthenticated, while the rest require only a low-privileged account. Our Virtual CISO Services (vCISO) helps identify ERPNext instances and other services reachable from the network, and an Implementation & Assessment Services penetration test and hardening review can validate that authorisation checks hold for your actual configuration and customisations.

Affected and fixed versions

ProductAffectedFixed in
GHSA-rv4r-c8v3-3hrc
ERPNext
– < 15.119.1
– < 16.32.0
15.119.1
16.32.0
1, 16.32.0
GHSA-v38v-9h2p-hr8v, GHSA-vr45-2p9x-3vjc, GHSA-wp9w-rxmg-6pfj, GHSA-5wpj-6rvp-9ff7
ERPNext
– < 15.121.0
– < 16.34.0
15.121.0
16.34.0
0, 16.34.0
GHSA-734c-hv9r-mg2c
ERPNext
– < 15.112.0
– < 16.23.0
15.112.0
16.23.0
0, 16.23.0
GHSA-f99r-gp2w-xghj
ERPNext
– < 15.120.0
– < 16.33.0
15.120.0
16.33.0
0, 16.33.0
GHSA-cgjf-xw8x-qjjc, GHSA-726x-68g4-fj9v
ERPNext
– < 15.121.3
– < 16.35.0
15.121.3
16.35.0
3, 16.35.0
GHSA-wwgm-3pv3-gmqh
ERPNext
– < 15.120.0
– < 16.23.0
15.120.0
16.23.0
0, 16.23.0

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them. Entries marked GHSA have no CVE: their source is the security advisory the maintainers published in their official GitHub repository.

Written with AI assistance from the sources above and checked automatically against them before publication.