Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Jan 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:frappe:erpnext:*:*:*:*:*:*:*:* |
Tue, 16 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1336 | |
| Metrics |
cvssV3_1
|
Mon, 15 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe erpnext |
|
| Vendors & Products |
Frappe
Frappe erpnext |
Mon, 15 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using frappe.render_template() with a context derived from the address_dict parameter, which can be either a dictionary or a string referencing an Address document. Although ERPNext uses a custom Jinja2 SandboxedEnvironment, dangerous functions like frappe.db.sql remain accessible via get_safe_globals(). An authenticated attacker with permission to create or modify an Address Template can inject arbitrary Jinja expressions into the template field. By creating an Address document with a matching country, and then calling the get_address_display API with address_dict="address_name", the system will render the malicious template using attacker-controlled data. This leads to server-side code execution or database information disclosure. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-16T15:18:05.186Z
Reserved: 2025-11-30T00:00:00.000Z
Link: CVE-2025-66437
Updated: 2025-12-16T15:11:46.283Z
Status : Analyzed
Published: 2025-12-15T18:15:48.290
Modified: 2026-01-05T18:19:07.300
Link: CVE-2025-66437
No data.
OpenCVE Enrichment
Updated: 2025-12-15T21:33:32Z