CVE-2026-36340
high
CVSS v3
8.1
CVSS v2
—
VIR risk
8.1
Description
Krayin CRM allows a remote attacker to execute arbitrary code via compose email function
Predictions
Exploit likelihood
88%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | krayin/laravel-crm | =2.1.5 | |
| Packagist | krayin/laravel-crm | >=2.1.5,<2.1.6 | 2.1.6 |
| COMPOSER | krayin/laravel-crm | = 2.1.5 | 2.1.6 |
References
- https://github.com/advisories/GHSA-32px-ccfx-cxq3
- https://drive.google.com/file/d/1yBdvbrXGf9fsFckmK9zTe2v8_vDtdicH/view
- https://github.com/cybercrewinc/CVE-2026-36340
- https://github.com/krayin/laravel-crm/releases/tag/v2.1.6
- https://nvd.nist.gov/vuln/detail/CVE-2026-36340
- https://github.com/krayin/laravel-crm
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.