CVE-2026-65974 | Frappe ERPNext up to 15.110.x/16.21.x Safe Execution frappe.render_template special elements in template engine
A vulnerability classified as critical has been found in Frappe ERPNext up to 15.110.x/16.21.x. This issue affects the function frappe.render_template of the component Safe Execution. The manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is traded as CVE-2026-65974. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More