Intel

AIKIDO-2026-487691

nono-cli is vulnerable to Improper Verification of Cryptographic Signature

Improper Verification of Cryptographic SignatureGHSA-6542-g6qc-gj95 Published 5 days ago

66

Medium Risk

This Affects:

RUSTnono-cli
0.0.1 - 0.77.0
Fixed in 0.78.0
Are you affected? Scan for Free

TL;DR

Pack trust-bundle verification skips a Sigstore entry when installed_path does not resolve to a file, and still returns success. The earlier artifact-hash loop uses the lockfile path, so a mismatched bundle path skips signer checks while the SHA256 check on the real artifact still passes. The fix fails closed when a bundle entry points at a missing path.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you install packs that re-verify stored Sigstore trust bundles.

Background info

nono-cli is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.1 - 0.77.0.

How to fix this

Upgrade the nono-cli library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform