Description
A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessageRequest of the file whatsapp-bridge/main.go of the component Send API Endpoint. This manipulation of the argument mediaPath causes path traversal. The exploit has been publicly disclosed and may be utilized. Patch name: 6657cdceadd361e8fbe824afe9d00b4504009a5d. It is recommended to apply a patch to fix this issue.
Problem types
Product status
Timeline
| 2026-05-31: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-05-31: | VulDB entry last update |
Credits
ybdesire (VulDB User)
References
vuldb.com/vuln/367544 (VDB-367544 | lharries whatsapp-mcp Send API Endpoint main.go SendMessageRequest path traversal)
vuldb.com/vuln/367544/cti (VDB-367544 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10264 (CVE-2026-10264 | CVE Analysis and Report)
vuldb.com/submit/824924 (Submit #824924 | lharries whatsapp-mcp v0.0.1 Path Traversal)
github.com/lharries/whatsapp-mcp/issues/241
github.com/BenGedi/whatsapp-mcp/pull/1
github.com/...ommit/6657cdceadd361e8fbe824afe9d00b4504009a5d
github.com/lharries/whatsapp-mcp/