{"id":"CVE-2025-52041","details":"In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the inventory_dimensions_dict parameter.","modified":"2026-07-15T01:49:20.645727699Z","published":"2025-10-01T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52041.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://github.com/Vietsunshine-Electronic-Solution-JSC/Vulnerability-Disclosures/blob/main/2025/Frappe%20Framework%20-%20Multiple%20SQL%20Injection.md"},{"type":"WEB","url":"https://github.com/frappe/erpnext/pull/49192/commits/eb22794f14351c2ff5731548c48bef0b91765c86"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52041.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52041"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/frappe/erpnext","events":[{"introduced":"2eb7a688cba73582e57f58905a8e68d401b92987"},{"last_affected":"2eb7a688cba73582e57f58905a8e68d401b92987"}],"database_specific":{"cpe":"cpe:2.3:a:frappe:erpnext:15.57.5:*:*:*:*:*:*:*","extracted_events":[{"introduced":"15.57.5"},{"last_affected":"15.57.5"}],"source":"CPE_STRING"}}],"versions":["15.57.5","v15.57.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52041.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}