Skip to content

💵 Bug Bounty – $2,100 if You Can Bypass WAHA API Key Validation #1076

Description

@devlikepro

👤 Human-Only Submissions

If you made the report with GPT/LLM/Agents - don’t send it.
GPT-generated crap will not be reviewed.
Give the human steps to follow, assuming we have WAHA installation already, just plain curl or commands

💵 Bug Bounty – $2,100 if You Can Bypass WAHA API Key Validation

Hi 👋
We're offering 2,100 USDT to anyone who can bypass the WAHA_API_KEY check on the WAHA HTTP API and:

  • Send a WhatsApp message
  • Or fetch the session list

Conditions:

  • Installed using the guide https://waha.devlike.pro/docs/how-to/install/
  • WAHA_API_KEY is a SHA-512 hash of a random UUIDv4
  • HTTPS connection (so you can not inspect the traffic)
  • devlikeapro/waha image is enough, no WAHA Plus required
  • No knowledge of the api key should be assumed

How to submit:
Email your exploit privately to waha@devlike.pro with steps, payloads, and evidence.

Notes:

  • First valid report wins (if reports about the same exploit)
  • No known or theoretical issues – must be reproducible
  • Related source code you can find in /src/core/auth folder!

Thanks for helping secure WAHA! 🙏

patron:PRO


Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions