top of page
perceptive_background_267k.jpg

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP ema…

Published:

28 July 2026 at 22:00:00

Alert date:

29 July 2026 at 23:00:29

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies, Ransomware & Malware, Email & Messaging, Data Breach & Exfiltration

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template used for rendering security OTP emails. The payload allows remote attackers to execute unauthorized code in any browser rendering the affected email template with JavaScript enabled. It establishes a WebSocket connection to a hardcoded command-and-control server, installs a password-field keylogger via MutationObserver, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite rendered pages. This represents a supply chain compromise where malicious code was inserted directly into the open-source CMS codebase. The vulnerability has been addressed in a commit to the official GitHub repository.

Technical details

Mitigation steps:

Affected products:

VaahCMS 2.0.0
VaahCMS 2.3.4

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page