{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/vaahcms-2.0.0-2.3.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-67595"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VaahCMS (2.0.0-2.3.4)"],"_cs_severities":["high"],"_cs_tags":["xss","credential-theft","web-security"],"_cs_type":"advisory","_cs_vendors":["VaahCMS"],"content_html":"\u003cp\u003eVaahCMS versions 2.0.0 through 2.3.4 are affected by a severe cross-site scripting (XSS) vulnerability involving an obfuscated JavaScript payload embedded directly within the Blade template engine responsible for rendering security OTP emails. When a user or administrator views an affected email in a browser with JavaScript enabled, the malicious script executes in the context of the user's session. The payload is highly sophisticated, utilizing MutationObserver to intercept password inputs as they are typed, scraping sensitive data from active WhatsApp Web sessions, and establishing persistent outbound WebSocket connections to attacker-controlled infrastructure. This compromise allows for full credential exfiltration and the ability to dynamically modify the rendered content of the application interface, presenting a critical risk for internal administrative account takeover.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies the hardcoded malicious JavaScript payload embedded within the VaahCMS security OTP Blade template files.\u003c/li\u003e\n\u003cli\u003eThe application triggers an automated security email (e.g., password reset or OTP verification) containing the malicious template.\u003c/li\u003e\n\u003cli\u003eThe victim opens the rendered email content in a web browser, triggering the execution of the obfuscated payload.\u003c/li\u003e\n\u003cli\u003eThe payload initializes a MutationObserver object to monitor the DOM for input field additions, specifically targeting password fields.\u003c/li\u003e\n\u003cli\u003eThe payload executes scraping logic to extract DOM content from active WhatsApp Web sessions if present in the browser state.\u003c/li\u003e\n\u003cli\u003eThe script establishes an outbound WebSocket connection to a pre-defined C2 domain for communication.\u003c/li\u003e\n\u003cli\u003eThe attacker issues remote commands via the WebSocket to exfiltrate stolen credentials and DOM data, or to redirect/modify the current page content.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for unauthenticated remote code execution within the victim's browser context. Successful exploitation leads to the theft of credentials and session data, potentially compromising administrative accounts or sensitive corporate communications handled within the browser. The scope is limited to users or administrators who render the malicious OTP email content in a browser environment, but the impact is high due to the nature of the data targeted (passwords and WhatsApp Web communications).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams to mitigate this vulnerability:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate VaahCMS installations immediately to a patched version beyond 2.3.4 to remove the malicious template code.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs and web application logs for unexpected WebSocket upgrade requests emanating from administrative dashboard endpoints.\u003c/li\u003e\n\u003cli\u003eDeploy Content Security Policy (CSP) headers that restrict the execution of inline scripts and define strict, allowlisted sources for WebSocket connections to prevent C2 communication.\u003c/li\u003e\n\u003cli\u003ePerform an integrity scan on all application Blade template files to check for obfuscated or unauthorized JavaScript blobs that do not match known-good source code.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T07:19:38Z","date_published":"2026-07-30T07:19:38Z","id":"https://feed.craftedsignal.io/briefs/2026-07-vaahcms-xss/","summary":"VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload in OTP email templates that executes unauthorized code in victim browsers, enabling credential theft and DOM manipulation.","title":"VaahCMS OTP Template Cross-Site Scripting and Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-07-vaahcms-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - VaahCMS (2.0.0-2.3.4)","version":"https://jsonfeed.org/version/1.1"}