1sealsemantic last-mile verification

Research / Finding

Snapshot transport accepts file paths outside its destination root

F-WHATSAPP-WARAFT-001

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

—score not recorded
WhatsApp/waraftReported fixWhatsApp/waraft

Snapshot transport accepts file paths outside its destination root

Fixed in: public source commit; a separate fixed release is not established

fixed on main (release not confirmed)
details
Finding IDs
F-WHATSAPP-WARAFT-001
Status
fixed on main (release not confirmed)
Fixed in
public source commit; a separate fixed release is not established
Note
Snapshot transport metadata from a connected Erlang peer supplies relative file paths that were joined to the receiving root without a confinement check. The 22 July 2026 patch validates every path with filelib:safe_relative_path/2 before creating transport state and rejects the whole transport if a path is unsafe. This covers parent traversal, absolute paths and symlink escapes handled by that check. The commit refers to an external security report, but does not by itself identify this finding's reporter. A fixed release and production rollout were not established. This is the waraft library and its peer trust boundary, not an unauthenticated attack on WhatsApp Messenger. Public-source review does not establish vendor attribution, an assigned severity or a fresh end-to-end retest.

F-WHATSAPP-WARAFT-001: File / path escapes. A peer-supplied snapshot path crosses the receiving transport's filesystem boundary. Reviewed 26 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-WHATSAPP-WARAFT-001

Security area (1seal assessment): Authorization. A peer-supplied snapshot path crosses the receiving transport's filesystem boundary. Reviewed 26 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.