Versions 0.1.1 or 0.1.2 of ipns are vulnerable to improper key validation. This is due to the public key verification was not being performed properly, resulting in any key being valid.
Update to version 0.1.3 or later.
{
"cwe_ids": [
"CWE-287"
],
"github_reviewed": true,
"github_reviewed_at": "2019-05-30T17:28:19Z",
"nvd_published_at": null,
"severity": "HIGH"
}