rootpwn

medium · CVSS v3 6.4 · CVSS v4 5.3

CVE-2026-96672

Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values refere…

Description

Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python paths to invoke non-whitelisted internal server-side methods and read their return values.

Scores

Severity
medium
CVSS v2
5.5
CVSS v3
6.4
CVSS v4
5.3
EPSS

← All CVEs