The verifyVerifiableCredential() method check the cryptographic integrity of the Verifiable Credential, but it does not check if the credential.issuer DID matches the signer of the credential.
The verifier is impacted by this vulnerability.
Patch will be available in version 0.2.2.
In case you trust certain issuers for certain credentials as a verifier, trust the issuer's public key from the credential.proof.verificationMethod field.
If you have any questions or comments about this advisory:
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2020-02-28T16:38:09Z",
"nvd_published_at": null,
"severity": "HIGH"
}