PatchSiren cyber security CVE debrief
CVE-2026-48543 krayin CVE debrief
CVE-2026-48543 is a stored client-side template injection vulnerability in Krayin CRM through version 2.2.6. Authenticated attackers can inject Vue.js template expressions into the web form description field, allowing execution of arbitrary JavaScript in other users' browsers when they view the affected web form. This vulnerability enables prototype chain traversal to retrieve the Function constructor and execute attacker-supplied JavaScript in the application origin for every user who views the affected web form.
- Vendor
- krayin
- Product
- laravel-crm
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-24
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-24
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for Krayin CRM installations, particularly those with authenticated access to web form descriptions, should assess exposure and potential impact. This includes reviewing web form descriptions for potential template injection, verifying Krayin CRM versions, and considering upgrades to patched versions if available. Security teams and vulnerability management teams should also prioritize verification of version 2.2.6 and earlier, and be
Why it matters
CVE-2026-48543 is a stored client-side template injection vulnerability in Krayin CRM that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers. Defenders responsible for Krayin CRM installations should assess exposure and potential impact, prioritizing verification of version 2.2.6 and earlier, and consider upgrading to a patched version if available.
- Execution of arbitrary JavaScript in users' browsers
- Potential for phishing or malicious actions through injected scripts
- Possible impact on user sessions or sensitive data exposure
- Need for verification of Krayin CRM version and exposure
Technical summary
The vulnerability allows authenticated attackers to inject Vue.js template expressions into the web form description field, enabling prototype chain traversal to retrieve the Function constructor and execute attacker-supplied JavaScript in the application origin for every user who views the affected web form. This can lead to execution of arbitrary JavaScript in users' browsers, potential for phishing or malicious actions through injected scripts, and possible impact on user sessions or sensitive data exposure. Defenders should prioritize verifying exposure of Krayin CRM installations to this vulnerability and assess the feasibility of exploitation within their environment.
Defensive priority
Defenders should prioritize verifying exposure of Krayin CRM installations to this vulnerability and assess the feasibility of exploitation within their environment.
Recommended defensive actions
- Verify Krayin CRM installations for exposure to this vulnerability
- Assess the feasibility of exploitation within the environment
- Review web form descriptions for potential template injection
- Consider upgrading to a patched version if available
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the corpus lacks specific information on affected versions beyond 2.2.6 and potential patches or mitigations. Defenders should verify Krayin CRM installations for exposure, review web form descriptions for potential template injection, and consider upgrading to a patched version if available. The vulnerability allows authenticated attackers to inject Vue.js template expressions into the web form description field.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48543 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48543
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48543 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48543
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-48541
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/krayin-crm-stored-template-injection-xss-via-web-form-description
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.