Server-Side Template Injection in ERPNext by Frappe
CVE-2025-66436
What is CVE-2025-66436?
A Server-Side Template Injection (SSTI) vulnerability exists in Frappe's ERPNext software due to insecure handling of user-supplied templates in the get_terms_and_conditions method. This flaw permits an authenticated user, who can create or modify Terms and Conditions documents, to inject arbitrary Jinja expressions. As a result, malicious users can execute unsafe code, including database queries, compromising the application's integrity and exposing sensitive information, such as database data. Despite the presence of a custom SandboxedEnvironment, dangerous global variables remain accessible, increasing the risk of exploit. Effective mitigation measures should be implemented to safeguard against such vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
