This was an error found by @metamania01 of the Audit Company Solshield.
It allowed one to verify a creator that did not sign by making use of a provision in Token Metadata that allows Creators who have signed compressed nfts to allow them to decompress with verified creators.
The issue is now patched. For more info see. https://twitter.com/thehasheddude/status/1601642138143375360
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2022-12-12T22:02:42Z",
"nvd_published_at": null,
"severity": "HIGH"
}