Snapshot transport accepts file paths outside its destination root
Fixed in: public source commit; a separate fixed release is not established
details
- Finding IDs
- F-WHATSAPP-WARAFT-001
- Status
- fixed on main (release not confirmed)
- Fixed in
- public source commit; a separate fixed release is not established
- Note
- Snapshot transport metadata from a connected Erlang peer supplies relative file paths that were joined to the receiving root without a confinement check. The 22 July 2026 patch validates every path with filelib:safe_relative_path/2 before creating transport state and rejects the whole transport if a path is unsafe. This covers parent traversal, absolute paths and symlink escapes handled by that check. The commit refers to an external security report, but does not by itself identify this finding's reporter. A fixed release and production rollout were not established. This is the waraft library and its peer trust boundary, not an unauthenticated attack on WhatsApp Messenger. Public-source review does not establish vendor attribution, an assigned severity or a fresh end-to-end retest.
F-WHATSAPP-WARAFT-001: File / path escapes. A peer-supplied snapshot path crosses the receiving transport's filesystem boundary. Reviewed 26 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-WHATSAPP-WARAFT-001
Security area (1seal assessment): Authorization. A peer-supplied snapshot path crosses the receiving transport's filesystem boundary. Reviewed 26 Sep 2026.