Intel

AIKIDO-2026-628161

agent-manifest is vulnerable to Improper Certificate Validation

Improper Certificate ValidationGHSA-mp83-94pc-7wqh Published 2 days ago

59

Medium Risk

This Affects:

PYTHONagent-manifest
0.0.1 - 0.11.2
Fixed in 0.12.0
Are you affected? Scan for Free

TL;DR

The TPM quote verification routine builds the attestation-key certificate chain without enforcing certificate validity periods, CA basic constraints, or key-usage certificate-signing restrictions. Expired, not-yet-valid, or non-CA intermediate certificates are accepted as long as the terminal certificate fingerprint matches a trusted root. An appraisal can then report a stronger certificate-backed result than the underlying evidence supports. The fix enforces validity windows and issuer authorization when validating the chain.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you verify TPM quotes whose attestation-key certificate chain is supplied by an untrusted party.

Background info

agent-manifest is vulnerable to Improper Certificate Validation in versions 0.0.1 - 0.11.2.

How to fix this

Upgrade the agent-manifest library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform