An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function
https://github.com/krayin/laravel-crm/releases/tag/v2.1.6
https://github.com/cybercrewinc/CVE-2026-36340
https://drive.google.com/file/d/1yBdvbrXGf9fsFckmK9zTe2v8_vDtdicH/view