PatchSiren cyber security CVE debrief
CVE-2026-97897 Krayin CVE debrief
A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting. The attack may be performed from remote. Upgrading to version 2.2.6 is capable of addressing this issue. The patch is identified as 734aa10ae6c2ffa4c96c8869a89aa66940e4d345.
- Vendor
- Krayin
- Product
- laravel-crm
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for Krayin laravel-crm deployments should assess exposure and prioritize upgrading to version 2.2.6 or later. This includes reviewing the official advisory, applying the patch, and monitoring for potential attacks. Security teams and vulnerability management teams should also review the affected component and plan for updates or mitigations through normal change control where exposure is confirmed. Additionally, operators and platform
Why it matters
Defenders should prioritize upgrading Krayin laravel-crm to version 2.2.6 or later to address the cross-site scripting vulnerability.
- Potential cross-site scripting attacks via TinyMCE Media Upload
- Need to verify affected versions and systems
- Priority on upgrading to version 2.2.6 or later
- Monitoring for potential attacks
Technical summary
The vulnerability affects Krayin laravel-crm up to 2.2.5, specifically in the TinyMCE Media Upload component of the Sanitizer.php file, allowing for cross-site scripting. The attack may be performed from remote locations. Upgrading to version 2.2.6 is capable of addressing this issue. The patch is identified as 734aa10ae6c2ffa4c96c8869a89aa66940e4d345. Defenders should assess exposure and prioritize upgrading to version 2.2.6 or later. The CVE record and source references provide information about the vulnerability, but further verification of affected versions and systems is required.
Defensive priority
Defenders should prioritize upgrading the affected component to version 2.2.6 or later.
Recommended defensive actions
- Upgrade the affected component to version 2.2.6 or later
- Review and apply the patch 734aa10ae6c2ffa4c96c8869a89aa66940e4d345
- Monitor for potential cross-site scripting attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source references provide information about the vulnerability in Krayin laravel-crm up to 2.2.5, affecting the TinyMCE Media Upload component, allowing for cross-site scripting. However, the scope of affected versions and systems requires further verification by defenders, who should check for exposure, review the official advisory, and apply the patch 734aa10ae6c2ffa4c96c8869a89aa66940e4d345. Evidence limits suggest that additional details may exist but are not currently verified.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97897 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97897
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97897 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97897
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/carlosalbertotuma/advisory/blob/main/advisory-03-stored-xss-tinymce-media-upload.md
-
Source reference
Unverified legacy reference
URL: https://github.com/krayin/laravel-crm/
-
Source reference
Unverified legacy reference
URL: https://github.com/krayin/laravel-crm/commit/734aa10ae6c2ffa4c96c8869a89aa66940e4d345
-
Source reference
Unverified legacy reference
URL: https://github.com/krayin/laravel-crm/pull/2639
-
Source reference
Unverified legacy reference
URL: https://github.com/krayin/laravel-crm/releases/tag/v2.2.6
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-97897
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/915413
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/409909
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.