CVE-2026-67595 Details
Description
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added inputs, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite the rendered page.
A vulnerability exists in VaahCMS versions 2.0.0 through 2.3.4, where a malicious, obfuscated JavaScript payload has been injected into the Blade template that renders security OTP emails. This allows remote attackers to execute unauthorized code in any browser that displays the affected email template with JavaScript enabled. The injected script creates a WebSocket connection to a predetermined command-and-control server, installs a keylogger for password fields using MutationObserver to track dynamically added inputs, scrapes content from WhatsApp Web, and accepts remote commands to redirect or modify the displayed page.
Users can update to VaahCMS version 2.3.5, which removes the malicious script from the affected Blade template.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 29, 2026CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-506 | Embedded Malicious Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| VaahCMS | >= 2.0.0, <= 2.3.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2026 | New CVE Received | [email protected] |
Volerion