Junglewise Threat Intelligence

CVE-2026-48063: Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be s

CVE-2026-48063 · Severity: critical · CVSS 4 · Published 2026-08-03

Executive brief

Baileys, a popular library for interacting with WhatsApp, contains a vulnerability that allows attackers to send fake messages that appear legitimate. An attacker can also corrupt the application's internal synchronization state or inject fake chat history. This could lead to misinformation, unauthorized data manipulation, and disruption of communication services for businesses relying on this library.

Technical details

A vulnerability in Baileys (WhiskeySockets) allows for message spoofing and app state corruption via maliciously crafted 'protocolMessage' payloads. By exploiting the 'placeholderResendMessage' functionality, a remote attacker can trigger a fake 'messages.upsert' event with a forged message key and payload. Additionally, the flaw permits the injection of fake key shares to corrupt the app state sync system and history sync spoofing to inject fake previous context. The issue is rooted in insufficient verification of data authenticity (CWE-345) and origin validation (CWE-346). Patches are available in versions 6.7.22 and 7.0.0-rc12.

Affected products

  • WhiskeySockets baileys < 6.7.22, >= 7.0.0-rc.1, < 7.0.0-rc12
  • WhiskeySockets @whiskeysockets/baileys < 6.7.22, >= 7.0.0-rc.1, < 7.0.0-rc12

Timeline

  • 2026-05-20: disclosed: Initial disclosure by purpshell
  • 2026-06-10: advisory: GitHub Advisory published

References