CVE-2024-45607

MEDIUM

Secreto31126 Whatsapp-api-js < 4.0.3 - Signature Verification Bypass

Title source: rule
STIX 2.1

Description

whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAPI.verifyRequestSignature and expect false when the signature is valid. Incorrect Access Control, anyone using the post or verifyRequestSignature methods to handle messages is impacted. This vulnerability is fixed in 4.0.3.

Scores

CVSS v3 5.8
EPSS 0.0091
EPSS Percentile 75.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-347
Status published
Products (2)
npm/whatsapp-api-js 4.0.0 - 4.0.3npm
secreto31126/whatsapp-api-js 4.0.0 - 4.0.3
Published Sep 12, 2024
Tracked Since Feb 18, 2026