CVE-2026-48540: Krayin CRM 2.2.6 Stored Template Injection XSS via Lead Title
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead title field. Attackers can craft a lead title containing double-brace template syntax that reaches the Vue template compiler, enabling prototype chain traversal to retrieve the Function constructor and execute attacker-supplied JavaScript in the application origin for every user who views the affected lead record.
Affected Software
Event History
Frequently Asked Questions
What access and interaction are required for exploitation?
An attacker needs authenticated access with low privileges to create or modify a lead title. A separate user must view the affected lead record for the injected JavaScript to execute in that user's browser.
Which deployments are known to be affected?
Krayin CRM versions through 2.2.6 are described as affected. The provided information does not state whether any configuration or deployment condition prevents exposure.
What is the expected security impact after a user views a malicious lead?
The attacker can execute supplied JavaScript in the application origin in the viewing user's browser. The supplied vector indicates low confidentiality and integrity impact and no availability impact.