@noble/ed25519 is vulnerable to Improper Verification of Cryptographic Signature
30
Low Risk
Affected versions of this package contain a low-severity issue in verify that could allow signatures generated by an attacker with access to a secret key to be accepted as valid for any message under that same key, weakening message-binding guarantees and primarily impacting systems that rely on non-repudiation. An attacker who obtains or controls a secret key could exploit this flaw by producing a signature once and reusing it to falsely assert authenticity over different messages, potentially undermining auditability, proof of origin, and trust in signed records.
You are affected if you are using a version that falls within the vulnerable range.
@noble/ed25519 is vulnerable to Improper Verification of Cryptographic Signature in versions 1.0.0 - 3.0.0.
Upgrade the @noble/ed25519 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant