Executive brief
Baileys, a popular library for interacting with WhatsApp, contains a vulnerability that allows attackers to send fake messages that appear legitimate. An attacker can also corrupt the application's internal synchronization state or inject fake chat history. This could lead to misinformation, unauthorized data manipulation, and disruption of communication services for businesses relying on this library.
Technical details
A vulnerability in Baileys (WhiskeySockets) allows for message spoofing and app state corruption via maliciously crafted 'protocolMessage' payloads. By exploiting the 'placeholderResendMessage' functionality, a remote attacker can trigger a fake 'messages.upsert' event with a forged message key and payload. Additionally, the flaw permits the injection of fake key shares to corrupt the app state sync system and history sync spoofing to inject fake previous context. The issue is rooted in insufficient verification of data authenticity (CWE-345) and origin validation (CWE-346). Patches are available in versions 6.7.22 and 7.0.0-rc12.
Affected products
- WhiskeySockets baileys < 6.7.22, >= 7.0.0-rc.1, < 7.0.0-rc12
- WhiskeySockets @whiskeysockets/baileys < 6.7.22, >= 7.0.0-rc.1, < 7.0.0-rc12
Timeline
- 2026-05-20: disclosed: Initial disclosure by purpshell
- 2026-06-10: advisory: GitHub Advisory published