Description
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added inputs, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite the rendered page.
Published: 2026-07-29
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious obfuscated JavaScript payload is embedded in the Blade template that renders security OTP emails. When a user’s browser processes the affected email with JavaScript enabled, the payload runs, establishing a WebSocket connection to a hardcoded command‑and‑control endpoint, installing a password‑field keylogger through a MutationObserver, scraping WhatsApp Web DOM content, and accepting remote commands to redirect or overwrite the rendered page. The result is unauthorized code execution in the browser environment, consistent with CWE‑506.

Affected Systems

VaahCMS versions 2.0.0 through 2.3.4 from the vendor webreinvent:vaahcms are affected. No narrower sub‑versions are specified. Users running any of these releases should assume the vulnerability is present.

Risk and Exploitability

The CVSS score of 9.2 indicates a high‑severity risk. The EPSS score of less than 1% suggests a low overall exploitation probability. The vulnerability is not listed in the CISA KEV catalog, so no known high‑profile exploitation data is available. The likely attack vector is an attacker delivering or manipulating an email that triggers the rendering of the compromised template in a victim’s browser. Exploitation requires the victim’s email system or client to execute HTML/JavaScript from the email, a common scenario for phishing or credential‑stealing attacks.

Generated by OpenCVE AI on August 2, 2026 at 07:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade VaahCMS to the latest release that removes the malicious content from security-otp.blade.php
  • If an upgrade is not immediately possible, delete or disable the security-otp.blade.php template so that OTP emails are rendered without executing embedded JavaScript
  • Implement an application‑level or browser content‑security policy that blocks WebSocket connections to external endpoints and prevents script execution from email templates

Generated by OpenCVE AI on August 2, 2026 at 07:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:webreinvent:vaahcms:*:*:*:*:*:*:*:*

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Webreinvent
Webreinvent vaahcms
Vendors & Products Webreinvent
Webreinvent vaahcms

Wed, 29 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added inputs, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite the rendered page.
Title VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
Weaknesses CWE-506
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Webreinvent Vaahcms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-14T16:50:58.023Z

Reserved: 2026-07-29T21:07:39.201Z

Link: CVE-2026-67595

cve-icon Vulnrichment

Updated: 2026-07-30T14:21:40.347Z

cve-icon NVD

Status : Deferred

Published: 2026-07-29T22:16:52.667

Modified: 2026-07-30T16:45:00.353

Link: CVE-2026-67595

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T07:45:03Z

Weaknesses