CVE-2025-52041 | Frappe ERPNext 15.57.5 stock_reconciliation.py get_stock_balance_for inventory_dimensions_dict sql injection
A vulnerability classified as critical was found in Frappe ERPNext 15.57.5. This vulnerability affects the function get_stock_balance_for of the file erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py. Such manipulation of the argument inventory_dimensions_dict leads to sql injection.
This vulnerability is listed as CVE-2025-52041. The attack may be performed from remote. There is no available exploit.
Applying a patch is advised to resolve this issue.