Vulnerability concerns a missing check in the ZK proof that enables an attack in which single malicious signer can reconstruct full private key.
cggmp21 v0.6.3 is a patch release that contains a fix that introduces this specific missing check.cggmp24 v0.7.0-alpha.2 in which we've introduced many other security checks as a precaution. Follow the migration guidelines to upgrade.Read our blog post to learn more.
{
"license": "CC0-1.0"
}