Skip to content

mautrix-whatsapp uses an unmaintained webp library, vulnerable to CVE-2023-4863 #650

@delroth

Description

@delroth

Hi!

https://github.com/chai2010/webp is a dependency of mautrix-whatsapp and is currently vulnerable to CVE-2023-4863. Unfortunately it also seems to be unmaintained (no commit in 18 months, long backlog of untriaged issues and PRs).

It's unclear to me what kind of exposure mautrix-whatsapp would have to CVE-2023-4863, but I suspect you'd be better off changing webp library anyway (maybe in favor of the pure-Go https://pkg.go.dev/golang.org/x/image/webp which happens to also be the more popular alternative).

cc @chvp
ref NixOS/nixpkgs#254798

Best,

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions