CVE-2026-67595
HIGHDescription
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added inputs, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite the rendered page.
Is your site exposed to CVE-2026-67595?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-67595? +
How severe is CVE-2026-67595? +
How do I check if I'm vulnerable to CVE-2026-67595? +
Related Vulnerabilities
simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken over after a phishing …
color-string is a parser and generator for CSS color strings. On 8 September 2025, the npm publishing account for color-string …
color is a Javascript color conversion and manipulation library. On 8 September 2025, the npm publishing account for color was …
debug is a JavaScript debugging utility. On 8 September 2025, the npm publishing account for debug was taken over after …
color-convert provides plain color conversion functions in JavaScript. On 8 September 2025, the npm publishing account for color-convert was taken …
backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken over after …