Unauthenticated Access Vulnerability in WhatsApp MCP Server by Very Good Plugins
CVE-2026-46555

7.7HIGH

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-46555?

The WhatsApp MCP Server has a vulnerability that allows unauthenticated local processes to access the messaging API and read sensitive files without authorization. The server listens on 127.0.0.1:8080 without requiring authentication or validating Host headers. This oversight enables both local and remote attackers to send messages, read files, and potentially exfiltrate sensitive information such as SSH keys and browser data as WhatsApp document attachments. The issue can be exploited through DNS rebinding attacks on web pages the user visits. Affected users are advised to upgrade to version 0.2.1, which includes critical security enhancements like bearer token authentication and directory confinement to mitigate these risks effectively.

Affected Version(s)

whatsapp-mcp < 0.2.1

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.