CVE-2025-66436 | Frappe ERPNext up to 15.89.0 Jinja2 Template render_template special elements used in a template engine
A vulnerability categorized as critical has been discovered in Frappe ERPNext up to 15.89.0. This affects the function render_template of the component Jinja2 Template Handler. The manipulation results in improper neutralization of special elements used in a template engine.
This vulnerability was named CVE-2025-66436. The attack may be performed from remote. There is no available exploit.