PatchSiren

verygoodplugins CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH verygoodplugins CVE published 2026-07-20

CVE-2026-46555

The WhatsApp MCP Server, enabling Claude to read and send WhatsApp messages, has vulnerabilities allowing unauthorized message sending and file reading due to lack of authentication and Host header validation. Users should be aware of these issues and address them to prevent unauthorized access and data exfiltration. The CVE record was published on 2026-07-20T17:17:09.820Z and has not been modified since [truncated]