Server-Side Template Injection Vulnerability in Frappe ERPNext
CVE-2025-66437
What is CVE-2025-66437?
A Server-Side Template Injection (SSTI) vulnerability exists in the get_address_display method of Frappe ERPNext versions before 15.89.0. This vulnerability allows authenticated attackers with permissions to modify an Address Template to inject malicious Jinja expressions into the template. Due to the configuration of the method, where the address_dict parameter can be tied to an Address document, attackers can leverage this to execute harmful scripts. The use of frappe.render_template() in conjunction with accessible functions via get_safe_globals() poses significant security risks, including unauthorized server-side code execution and potential exposure of sensitive database information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
