CVE-2026-46555 | verygoodplugins whatsapp-mcp up to 0.2.0 whatsapp-bridge HTTP API /api/send media_path path traversal
A vulnerability, which was classified as critical, was found in verygoodplugins whatsapp-mcp up to 0.2.0. Affected is an unknown function of the file /api/send of the component whatsapp-bridge HTTP API. The manipulation of the argument media_path results in path traversal.
This vulnerability is identified as CVE-2026-46555. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More