risc0-zkvm is vulnerable to Insufficient Verification of Data Authenticity
75
High Risk
The RISC Zero zkVM executes certain RISC-V instructions across multiple proving cycles, using a major mode set during the first cycle to control how the following cycle proceeds. The circuit does not impose a constraint ensuring that the mode of operation was definitively selected by the previous cycle. A malicious prover can leverage this under-constrained behavior to craft invalid proofs that still pass verification, breaking the soundness guarantees of the proof system. The fix adds constraints that require the mode to have been set by the preceding cycle.
You are affected if you are using a version that falls within the vulnerable range.
risc0-zkvm is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.1 - 1.1.0.
Upgrade the risc0-zkvm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant