GHSA-xp5g-jhg3-3rg2

Source
https://github.com/advisories/GHSA-xp5g-jhg3-3rg2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-xp5g-jhg3-3rg2/GHSA-xp5g-jhg3-3rg2.json
Aliases
Published
2023-05-22T00:30:20Z
Modified
2023-11-08T04:12:40.305994Z
Details

iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.

References

Affected packages

npm / snarkjs

Package

Name
snarkjs

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Last affected
0.6.11