CVE-2026-10264
LOW
2,0
Source: [email protected]
Attack Vector: adjacent
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW
3,5
Source: [email protected]
Attack Vector: adjacent_network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
LOW
2,7
Source: [email protected]
Access Vector: adjacent_network
Access Complexity: low
Authentication: single
Confidentiality: partial
Integrity: none
Availability: none
Description
AI Translation Available
A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessageRequest of the file whatsapp-bridge/main.go of the component Send API Endpoint. This manipulation of the argument mediaPath causes path traversal. The exploit has been publicly disclosed and may be utilized. Patch name: 6657cdceadd361e8fbe824afe9d00b4504009a5d. It is recommended to apply a patch to fix this issue.
22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
StableCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Modify Files Or Directories
Read Files Or Directories
Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies:
AI/ML
https://github.com/BenGedi/whatsapp-mcp/commit/6657cdceadd361e8fbe824afe9d00b45…
https://github.com/BenGedi/whatsapp-mcp/pull/1
https://github.com/lharries/whatsapp-mcp/
https://github.com/lharries/whatsapp-mcp/issues/241
https://vuldb.com/cve/CVE-2026-10264
https://vuldb.com/submit/824924
https://vuldb.com/vuln/367544
https://vuldb.com/vuln/367544/cti