CVE Explorer
CVE-2026-46555
WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint accepts an absolute `media_path` parameter without confining it to a safe directory. Combined, these issues allow any local process running as the same user as the bridge to send WhatsApp messages from
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:640499dd5a542a8d3a5288e3c398738f26bbe95427ae6e8efd4c780612af997d · sha256:35d0f4541b224d6d… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:640499dd5a542a8d3a5288e3c398738f26bbe95427ae6e8efd4c780612af997d · sha256:35d0f4541b224d6d… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-346","description":"CWE-346: Origin Validation Error","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:640499dd5a542a8d3a5288e3c398738f26bbe95427ae6e8efd4c780612af997d · sha256:35d0f4541b224d6d… · /containers/cna/problemTypes/2/descriptions/0
Affected products and versions
1 source assertion{"product":"whatsapp-mcp","vendor":"verygoodplugins","versions":[{"status":"affected","version":"< 0.2.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:640499dd5a542a8d3a5288e3c398738f26bbe95427ae6e8efd4c780612af997d · sha256:35d0f4541b224d6d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:640499dd5a542a8d3a5288e3c398738f26bbe95427ae6e8efd4c780612af997d · sha256:35d0f4541b224d6d… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
3 source assertions{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:640499dd5a542a8d3a5288e3c398738f26bbe95427ae6e8efd4c780612af997d · sha256:35d0f4541b224d6d… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:640499dd5a542a8d3a5288e3c398738f26bbe95427ae6e8efd4c780612af997d · sha256:35d0f4541b224d6d… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-346","description":"CWE-346: Origin Validation Error","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:640499dd5a542a8d3a5288e3c398738f26bbe95427ae6e8efd4c780612af997d · sha256:35d0f4541b224d6d… · /containers/cna/problemTypes/2/descriptions/0
Source references
3 source assertions{"name":"https://github.com/verygoodplugins/whatsapp-mcp/blob/main/SECURITY.md","tags":["x_refsource_MISC"],"url":"https://github.com/verygoodplugins/whatsapp-mcp/blob/main/SECURITY.md"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:640499dd5a542a8d3a5288e3c398738f26bbe95427ae6e8efd4c780612af997d · sha256:35d0f4541b224d6d… · /containers/cna/references/1
{"name":"https://github.com/verygoodplugins/whatsapp-mcp/releases/tag/v0.2.1","tags":["x_refsource_MISC"],"url":"https://github.com/verygoodplugins/whatsapp-mcp/releases/tag/v0.2.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:640499dd5a542a8d3a5288e3c398738f26bbe95427ae6e8efd4c780612af997d · sha256:35d0f4541b224d6d… · /containers/cna/references/2
{"name":"https://github.com/verygoodplugins/whatsapp-mcp/security/advisories/GHSA-7jj9-4qqq-4xc4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/verygoodplugins/whatsapp-mcp/security/advisories/GHSA-7jj9-4qqq-4xc4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:640499dd5a542a8d3a5288e3c398738f26bbe95427ae6e8efd4c780612af997d · sha256:35d0f4541b224d6d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.