Stable release with baileys >= 7.0.0-rc.12 (CVE-2026-48063) — is 2.4.0 planned?
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 20/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Quiet
- Tech stack
- typescript
Research direction
Review package.json on develop and the dependency update merged in #2575, then compare it with the stable v2.3.7 release. Check the CVE-2026-48063 advisory and current release process to determine whether a stable 2.4.0 or a patched 2.3.x path is documented; done means a maintainer-confirmed release plan or mitigation guidance.
Written by the indexing model from the issue text.
Description
Context
CVE-2026-48063 / GHSA-qvv5-jq5g-4cgg (CVSS 9.3) affects baileys >= 7.0.0-rc.1, < 7.0.0-rc.12, allowing a remote party to inject a forged messages.upsert with attacker-chosen key and payload.
The latest stable release, v2.3.7 (2025-12-05), ships "baileys": "7.0.0-rc.9" — inside the affected range — and main still declares rc.9 today.
The dependency was already bumped to 7.0.0-rc13 on develop in #2575 (merged 2026-06-15), where package.json now reads version 2.4.0.
Question
Is a stable 2.4.0 release planned, and is there an ETA?
For production deployments that cannot run homolog/develop builds, is there a recommended path to the patched baileys — for example a 2.3.x patch release that only bumps the dependency?
Why it matters
We run v2.3.7 in production. As an interim mitigation we drop inbound payloads carrying requestId / protocolMessage at our webhook boundary (the workaround from the advisory), but that only covers events Evolution forwards — it cannot cover anything handled internally.
Thanks for the project and for any guidance.
- Dominant language
- TypeScript
- Stars
- 9.6k
- Forks
- 7.3k
- PR merge metrics
- No merged PRs in 30d
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from evolution-foundation/evolution-api
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
evolution-foundation/evolution-api#2700 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
All issues in evolution-foundation/evolution-api
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
safetrustcr/dApp-SafeTrust#426 ·
-
area:workflow bug ready-for-agent
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
fil-donadoni/tolaria#4409 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Fission-AI/OpenSpec#1960 ·
-
Add dependabot Open
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
corsairdev/corsair#1764 ·