CVE-2026-67530
WACRM: SSRF via the automation `send_webhook` action
CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
0th
WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/automations/engine.ts and its validation in src/lib/automations/validate.ts allowed an authenticated user with automation privileges to submit an arbitrary webhook URL that the server fetched without the existing isDeliverableUrl SSRF guard in src/lib/webhooks/ssrf.ts, allowing requests to private, loopback, link-local, or cloud metadata addresses such as the cloud metadata endpoint at 169.254.169.254. This vulnerability is fixed with commit 23838a9959550e975d732ae08a44a3a2f0cc084b.
| CWE | CWE-918 |
| Vendor | arnasdon |
| Product | wacrm |
| Published | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for arnasdon wacrm
Be the first to know when new medium vulnerabilities affecting arnasdon wacrm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
ArnasDon / wacrm
<= 0.7.0