Junglewise Threat Intelligence

CVE-2026-10264: lharries whatsapp-mcp path traversal in Send API Endpoint

CVE-2026-10264 · Severity: low · CVSS 3.5 · Published 2026-06-01

Executive brief

A security vulnerability exists in the lharries whatsapp-mcp tool, which is used to connect WhatsApp to AI agents. An attacker with access to the local network could exploit this flaw to read sensitive files from the computer running the software. This could lead to the exposure of private data, system configuration files, or other confidential information.

Technical details

A path traversal vulnerability (CWE-22) exists in the 'SendMessageRequest' function within 'whatsapp-bridge/main.go' of lharries whatsapp-mcp 0.0.1. The 'mediaPath' parameter provided to the '/api/send' endpoint is passed directly to 'os.ReadFile' without validation or sanitization. An attacker with access to the API endpoint (typically reachable via the local network or adjacent network) can use traversal sequences like '../' to read arbitrary files on the host system that the process has permissions to access. A patch has been developed (commit 6657cdc) which implements 'validateMediaPath' to ensure paths are absolute and restricted to authorized directories.

Affected products

  • lharries whatsapp-mcp 0.0.1

Timeline

  • 2026-05-10: disclosed: Issue reported on GitHub
  • 2026-05-30: patched: Fix committed to repository
  • 2026-06-01: advisory: CVE published

References