CVE-2026-48063
Received Received - Intake

Message Spoofing in Baileys WhatsApp Web API

Vulnerability report for CVE-2026-48063, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: GitHub, Inc.

Description

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This allows anyone to spoof messages. The same exploit also allows an attacker to corrupt the app state sync system by sending fake key shares, and also allows for history sync spoofing which also serves the same problem, injecting fake previous context or "on-demand" sync. This issue has been fixed in versions 6.7.22 and 7.0.0-rc12.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
baileys baileys to 6.7.22|end_excluding=7.0.0-rc12 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Baileys, a WhatsApp Web API, in versions before 6.7.22 and 7.0.0-rc12. Attackers can send malicious payloads via placeholderResendMessage to spoof messages, corrupt app state sync, and inject fake previous context or history sync.

Detection Guidance

This vulnerability involves spoofed messages and corrupted app state sync in Baileys. Detection requires monitoring for unexpected message events or sync anomalies. Check Baileys logs for fake messages.upsert events or unusual key shares. Inspect network traffic for unauthorized WhatsApp Web API interactions. No specific commands are provided in the context.

Impact Analysis

An attacker could impersonate you or others in WhatsApp chats, send fake messages under your name, or manipulate chat history. This could lead to misinformation, fraud, or reputational damage if used maliciously.

Compliance Impact

This vulnerability allows spoofing of messages and corruption of app state sync, which could lead to unauthorized data manipulation or false records. This may impact compliance with GDPR (data integrity, accountability) and HIPAA (integrity of health data) by enabling false information to be inserted into systems handling sensitive data.

Mitigation Strategies

Update Baileys to version 6.7.22 or 7.0.0-rc12 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48063. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart