CVE-2026-31017
A vulnerability in the Print Format feature of ERPNext and the Frappe Framework allows an attacker to inject malicious HTML code. When the system generates a PDF from this code, it can be tricked into making unauthorized requests to internal servers.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users running ERPNext version 16.0.1 or Frappe Framework version 16.1.1.
Real-world impact
An attacker could force the server to access private internal services or cloud metadata endpoints, which could lead to the theft of sensitive information.
Why this severity
This is rated as critical because an attacker can exploit it remotely over the network without needing any special privileges or user interaction.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Apr 8, 2026 · Apr 8, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 25, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- github.com/PhDg1410/CVE/tree/main/CVE-…third party advisory