9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (body_text) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals such as frappe.db.sql are still available in the execution context via get_safe_globals(). An authenticated attacker with access to configure Dunning Type and its child table Dunning Letter Text can inject arbitrary Jinja expressions, resulting in server-side code execution within a restricted but still unsafe context. This can leak database information.
AI Analysis
Server-Side Template Injection vulnerability in Frappe ERPNext, allowing server-side code execution
Basic Information
ID
CVE-2025-66434
Source
mitre
Published
Dec 15, 2025 at 00:00
Modified
Dec 16, 2025 at 15:31
Affected Product
Vendor
Frappe Technologies
Product
ERPNext
Version
15.89.0
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Frappe Technologies
Product
ERPNext
Version
15.89.0