A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs from user-controlled HTML content, the application allows the inclusion of HTML elements such as <iframe> that reference external resources. The PDF rendering engine automatically fetches these resources on the server side. An attacker can abuse this behavior to force the server to make arbitrary HTTP requests to internal services, including cloud metadata endpoints, potentially leading to sensitive information disclosure.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Apr 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SSRF in ERPNext PDF Rendering Allows Server‑Side Requests |
Thu, 09 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe erpnext Frappe framework |
|
| Vendors & Products |
Frappe
Frappe erpnext Frappe framework |
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SSRF in ERPNext PDF Rendering Allows Server‑Side Requests | |
| Weaknesses | CWE-918 |
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs from user-controlled HTML content, the application allows the inclusion of HTML elements such as <iframe> that reference external resources. The PDF rendering engine automatically fetches these resources on the server side. An attacker can abuse this behavior to force the server to make arbitrary HTTP requests to internal services, including cloud metadata endpoints, potentially leading to sensitive information disclosure. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-04-08T00:00:00.000Z
Updated: 2026-04-09T20:49:57.487Z
Reserved: 2026-03-09T00:00:00.000Z
Link: CVE-2026-31017
No data.
Status : Undergoing Analysis
Published: 2026-04-08T17:21:18.737
Modified: 2026-04-09T21:16:08.373
Link: CVE-2026-31017
No data.