ERPNext Path Traversal Vulnerability Allowing Arbitrary File Read

Vulnerability

A path traversal vulnerability has been identified in ERPNext, an open-source Enterprise Resource Planning tool. This vulnerability, present in versions prior to 15.101.1 and 16.10.0, allows authenticated adjacent attackers to read arbitrary files by exploiting an endpoint that improperly restricts pathname limitations. The issue has been addressed in the mentioned patched versions.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server.

Remediation

Users are advised to upgrade to ERPNext versions 15.101.1 or 16.10.0.

Added: May 13, 2026, 10:23 PM
Updated: May 13, 2026, 10:23 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.6
exploitability
4.9
remediation
7.7
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.