PT-2026-48544 · Baileys · Baileys
CVE-2026-48063
·
Published
2026-06-10
·
Updated
2026-08-03
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Baileys versions prior to 6.7.22
Baileys versions prior to 7.0.0-rc12
Description
An authentication-bypass-by-spoofing flaw allows a remote unauthenticated attacker to send a maliciously crafted
protocolMessage payload via the placeholderResendMessage endpoint. This action triggers a fake messages.upsert event containing an attacker-controlled message key and payload, enabling the spoofing of arbitrary inbound messages on a target session. Additionally, this vector can be used to corrupt the app state sync system by sending forged key shares and to perform history-sync spoofing, which allows the injection of fake previous conversation context or bogus on-demand sync data.Recommendations
Update to version 6.7.22.
Update to version 7.0.0-rc12.
As a temporary mitigation, drop
messages.upsert events that contain a requestId field.
Disable automatic history sync by setting shouldSyncHistoryMessage: () => false in the socket configuration.Exploit
Fix
Authentication Bypass by Spoofing
Insufficient Verification of Data Authenticity
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Baileys