CVE-2026-72911 | Frappe ERPNext up to 15.117.x/16.28.x Template Rendering process_statement_of_accounts.py render_template pdf_name code injection

SecurityVulns

A vulnerability identified as critical has been detected in Frappe ERPNext up to 15.117.x/16.28.x. This vulnerability affects the function render_template of the file erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py of the component Template Rendering. This manipulation of the argument pdf_name causes code injection.

This vulnerability is tracked as CVE-2026-72911. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component.VulDB Recent EntriesRead More