Ghostwire

CVE-2026-6979: A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file...

MEDIUM CVSS 6.3 Exploit Available 1 PoC

Published: April 25, 2026 | Last Modified: April 25, 2026

Description

A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Proof-of-Concept Exploits (1)

Security Coverage (1 articles)

References