OpenWA vulnerabilities
CVEs whose affected-version data names the OpenWA package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-91161Medium· 6.4OpenWA is a free, open source, self-hosted WhatsApp API gateway
OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the GET /api/sessions/{sessionId}/groups/{groupId}/invite-code endpoint and the GroupGetInviteCode MCP tool have no OPERATOR role requirement, allowing a v…
▾ Sunlitrmyndharis · OpenWAvia NVD
CVE-2026-91160High· 8.2OpenWA is a free, open source, self-hosted WhatsApp API gateway
OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers the session.qr event to a VIEWER API key that subscribes by event name or through either wildcard subscription form,…
▾ Twilightrmyndharis · OpenWAvia NVD