PT-2026-48544 · Baileys · Baileys

CVE-2026-48063

·

Published

2026-06-10

·

Updated

2026-08-03

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Baileys versions prior to 6.7.22 Baileys versions prior to 7.0.0-rc12
Description An authentication-bypass-by-spoofing flaw allows a remote unauthenticated attacker to send a maliciously crafted protocolMessage payload via the placeholderResendMessage endpoint. This action triggers a fake messages.upsert event containing an attacker-controlled message key and payload, enabling the spoofing of arbitrary inbound messages on a target session. Additionally, this vector can be used to corrupt the app state sync system by sending forged key shares and to perform history-sync spoofing, which allows the injection of fake previous conversation context or bogus on-demand sync data.
Recommendations Update to version 6.7.22. Update to version 7.0.0-rc12. As a temporary mitigation, drop messages.upsert events that contain a requestId field. Disable automatic history sync by setting shouldSyncHistoryMessage: () => false in the socket configuration.

Exploit

Fix

Authentication Bypass by Spoofing

Insufficient Verification of Data Authenticity

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48063
GHSA-QVV5-JQ5G-4CGG

Affected Products

Baileys