PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48543 krayin CVE debrief

CVE-2026-48543 is a stored client-side template injection vulnerability in Krayin CRM through version 2.2.6. Authenticated attackers can inject Vue.js template expressions into the web form description field, allowing execution of arbitrary JavaScript in other users' browsers when they view the affected web form. This vulnerability enables prototype chain traversal to retrieve the Function constructor and execute attacker-supplied JavaScript in the application origin for every user who views the affected web form.

Vendor
krayin
Product
laravel-crm
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-25
Advisory published
2026-09-24
Advisory updated
2026-09-25

Who should care

Defenders responsible for Krayin CRM installations, particularly those with authenticated access to web form descriptions, should assess exposure and potential impact. This includes reviewing web form descriptions for potential template injection, verifying Krayin CRM versions, and considering upgrades to patched versions if available. Security teams and vulnerability management teams should also prioritize verification of version 2.2.6 and earlier, and be

Why it matters

CVE-2026-48543 is a stored client-side template injection vulnerability in Krayin CRM that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers. Defenders responsible for Krayin CRM installations should assess exposure and potential impact, prioritizing verification of version 2.2.6 and earlier, and consider upgrading to a patched version if available.

  • Execution of arbitrary JavaScript in users' browsers
  • Potential for phishing or malicious actions through injected scripts
  • Possible impact on user sessions or sensitive data exposure
  • Need for verification of Krayin CRM version and exposure

Technical summary

The vulnerability allows authenticated attackers to inject Vue.js template expressions into the web form description field, enabling prototype chain traversal to retrieve the Function constructor and execute attacker-supplied JavaScript in the application origin for every user who views the affected web form. This can lead to execution of arbitrary JavaScript in users' browsers, potential for phishing or malicious actions through injected scripts, and possible impact on user sessions or sensitive data exposure. Defenders should prioritize verifying exposure of Krayin CRM installations to this vulnerability and assess the feasibility of exploitation within their environment.

Defensive priority

Defenders should prioritize verifying exposure of Krayin CRM installations to this vulnerability and assess the feasibility of exploitation within their environment.

Recommended defensive actions

  • Verify Krayin CRM installations for exposure to this vulnerability
  • Assess the feasibility of exploitation within the environment
  • Review web form descriptions for potential template injection
  • Consider upgrading to a patched version if available
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the corpus lacks specific information on affected versions beyond 2.2.6 and potential patches or mitigations. Defenders should verify Krayin CRM installations for exposure, review web form descriptions for potential template injection, and consider upgrading to a patched version if available. The vulnerability allows authenticated attackers to inject Vue.js template expressions into the web form description field.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48543 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48543

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48543 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48543

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.