Intel

AIKIDO-2026-191868

agent-manifest is vulnerable to Insufficient Verification of Data Authenticity

Insufficient Verification of Data AuthenticityGHSA-q8mp-875w-2w53 Published 2 days ago

31

Low Risk

This Affects:

PYTHONagent-manifest
0.0.1 - 0.11.2
Fixed in 0.12.0
Are you affected? Scan for Free

TL;DR

The human-in-the-loop approval approval_method field is not part of the signed pre-image, so it can be altered after signing without invalidating the approval signature. Changing a software-key approval to a hardware-key value keeps the original signature valid while raising the reported approval strength. This can satisfy method-sufficiency checks at conformance level 2 that the original approval should not meet. The fix binds the approval method into the authenticated approval data.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you rely on level-2 human-in-the-loop approval-method sufficiency checks.

Background info

agent-manifest is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.1 - 0.11.2.

How to fix this

Upgrade the agent-manifest library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform