


Perceptive Security
SOC/SIEM Consultancy

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP ema…
Published:
29 July 2026 at 00:00:00
Alert date:
30 July 2026 at 01:00:29
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies, Ransomware & Malware, Email & Messaging, Data Breach & Exfiltration
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template used for rendering security OTP emails. The payload allows remote attackers to execute unauthorized code in any browser rendering the affected email template with JavaScript enabled. It establishes a WebSocket connection to a hardcoded command-and-control server, installs a password-field keylogger via MutationObserver, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite rendered pages. This represents a supply chain compromise where malicious code was inserted directly into the open-source CMS codebase. The vulnerability has been addressed in a commit to the official GitHub repository.
Technical details
Mitigation steps:
Affected products:
VaahCMS 2.0.0
VaahCMS 2.3.4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67595
https://github.com/webreinvent/vaahcms/commit/8d7898f7a385a5fade1180a9b664ff158d873129
https://github.com/webreinvent/vaahcms/pull/317
https://www.vulncheck.com/advisories/vaahcms-malicious-javascript-supply-chain-via-security-otp-blade-php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
