Frappe-ErpNext-AuthBypass-SSTItoRCE.A critical vulnerability in ERPNext’s Jinja templating implementation allows SSTI attacks that result in remote code execution. Combined with an account hijacking flaw, this enables unauthenticated attackers to fully compromise the system.