CVE-2025-66438 | Frappe ERPNext up to 15.89.0 API get_html_and_style special elements used in a template engine
A vulnerability identified as critical has been detected in Frappe ERPNext up to 15.89.0. This impacts the function get_html_and_style of the component API. This manipulation causes improper neutralization of special elements used in a template engine.
The identification of this vulnerability is CVE-2025-66438. It is possible to initiate the attack remotely. There is no exploit available.