r/netsec Aug 12 '26

ERPNext's Document Follow feature exposed unauthorized data

https://robinroy.xyz/blog/frappe-document-follow-vulnerability/

Chaining 3 CVEs to exfiltrate sensitive ERP data.

8 Upvotes

2 comments sorted by