From 49df1afca746f0f23d55551eb0e0a967268bba68 Mon Sep 17 00:00:00 2001 From: Adkali Date: Thu, 29 Jan 2026 04:02:15 +0200 Subject: [PATCH] Improve GHSA-hp4v-q7qc-45wr --- .../GHSA-hp4v-q7qc-45wr.json | 28 +++++++++++++++++-- 1 file changed, 25 insertions(+), 3 deletions(-) diff --git a/advisories/unreviewed/2025/04/GHSA-hp4v-q7qc-45wr/GHSA-hp4v-q7qc-45wr.json b/advisories/unreviewed/2025/04/GHSA-hp4v-q7qc-45wr/GHSA-hp4v-q7qc-45wr.json index db1b60ed74e17..61a4f83b25a44 100644 --- a/advisories/unreviewed/2025/04/GHSA-hp4v-q7qc-45wr/GHSA-hp4v-q7qc-45wr.json +++ b/advisories/unreviewed/2025/04/GHSA-hp4v-q7qc-45wr/GHSA-hp4v-q7qc-45wr.json @@ -1,19 +1,37 @@ { "schema_version": "1.4.0", "id": "GHSA-hp4v-q7qc-45wr", - "modified": "2025-04-09T18:30:49Z", + "modified": "2025-04-09T18:31:51Z", "published": "2025-04-07T15:31:10Z", "aliases": [ "CVE-2025-30401" ], - "details": "A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension. A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than view the attachment when manually opening the attachment inside WhatsApp.", + "summary": "CVE-2025-30401", + "details": "A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension. A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than view the attachment when manually opening the attachment inside WhatsApp.\n\nAcknowledgment: External Researcher - Adam Kahlon.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", @@ -23,6 +41,10 @@ "type": "WEB", "url": "https://www.facebook.com/security/advisories/cve-2025-30401" }, + { + "type": "PACKAGE", + "url": "https://www.linkedin.com/posts/adkali_cve202530401-poc-whatsapp-activity-7318190804584300544-InQC" + }, { "type": "WEB", "url": "https://www.whatsapp.com/security/advisories/2025"