Server-Side Request Forgery Vulnerability in WACRM by Arnas Don
CVE-2026-67530
6.4MEDIUM
What is CVE-2026-67530?
WACRM, a self-hostable CRM template for WhatsApp, contains a vulnerability that allows an authenticated user with automation privileges to submit arbitrary webhook URLs. In versions 0.7.0 and earlier, the server can fetch these URLs due to a lack of proper validation, bypassing the isDeliverableUrl SSRF guard. This can lead to unauthorized access to private resources, including cloud metadata endpoints and other sensitive internal services.
Affected Version(s)
wacrm <= 0.7.0
