CVE-2026-6979 | devlikeapro WAHA up to 2026.3.4 API Request media.controller.ts server-side request forgery
A vulnerability, which was classified as critical, has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes server-side request forgery.
This vulnerability is handled as CVE-2026-6979. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.