VULNERABILITY OVERVIEW CVE-2026-31017 is a Server-Side Request Forgery vulnerability affecting ERPNext v16.0.1 and Frappe Framework v16.1.1. The flaw exists in the Print Format functionality where insufficient sanitization of user-supplied HTML allows attackers to inject elements like iframes that trigger server-side resource fetching during PDF generation. This enables attackers to force the application server to make arbitrary HTTP requests to internal services and cloud metadata endpoints. SEVERITY ASSESSMENT The vulnerability carries a CVSS 3.1 score of 9.1 CRITICAL with a network-based attack vector requiring no authentication or user interaction. Attack complexity is low, indicating ease of exploitation. The vulnerability has high confidentiality and integrity impact, potentially allowing disclosure of sensitive system information and internal service data. The EPSS score of 0.00039 indicates current exploitation probability is low relative to the broader vulnerability landscape. EXPLOITATION STATUS There is no evidence of active exploitation, with the vulnerability absent from known exploited vulnerabilities (KEV) databases and the Hot List remaining inactive. No public exploit code availability has been reported. Current community attention appears limited given the low EPSS score, though the critical CVSS rating warrants immediate patching for affected organizations using the vulnerable ERPNext and Frappe Framework versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.0.1CPE matchmatch criteria | cpe:2.3:a:frappe:erpnext:16.0.1:*:*:*:*:*:*:* | ||
16.1.1CPE matchmatch criteria | cpe:2.3:a:frappe:frappe:16.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.