An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email functionReferenceshttps://drive.google.com/file/d/1yBdvbrXGf9fsFckmK9zTe2v8_vDtdicH/viewhttps://github.com/krayin/laravel-crm/releases/tag/v2.1.6https://github.com/cybercrewinc/CVE-2026-36340