Junglewise Threat Intelligence

CVE-2026-38527: Webkul Krayin CRM SSRF in Webhook Creation

CVE-2026-38527 · Severity: high · CVSS 8.5 · Published 2026-04-14

Technologies: Webkul Krayin CRM, krayin/laravel-crm (Packagist). Vendors: Webkul, Packagist.

Executive brief

Webkul Krayin CRM, an open-source customer relationship management platform, contains a vulnerability in its webhook automation feature. An authenticated user can trick the CRM server into making unauthorized requests to internal systems that are not normally accessible from the internet. This could allow an attacker to scan the internal corporate network, access sensitive cloud metadata (such as AWS/GCP credentials), or interact with internal databases, potentially leading to a broader breach of the organization's infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Webkul Krayin CRM v2.2.x within the '/settings/webhooks/create' component. The application fails to validate or restrict the 'end_point' parameter in the WebhookService.php and WebhookRequest.php files, allowing it to accept internal IP addresses and non-routable ranges (RFC 1918, loopback, and cloud metadata endpoints like 169.254.169.254). An authenticated attacker with low privileges can create a crafted webhook and trigger its execution to perform internal port scanning or retrieve sensitive data from internal APIs and cloud instance metadata services. As of the advisory date, no official patch has been confirmed, though mitigations include implementing URL allowlists and blocking private IP ranges at the application or network level.

Affected products

  • Webkul Krayin CRM (laravel-crm) <= 2.2.0

Timeline

  • 2026-04-14: disclosed: NVD and GitHub Advisory published
  • 2026-04-16: advisory: GitHub Advisory reviewed and updated

References

Related threats