nostr is vulnerable to Improper Verification of Data Authenticity
75
High Risk
The NIP-47 response and notification parsers and the NIP-60 wallet event parsers decrypt relay-provided events before verifying the event kind, computed id, signature, and expected wallet public key. Because the decryption peer is derived from the untrusted event author, successful decryption does not prove the configured wallet produced the event. A malicious relay can deliver an attacker-signed event that is parsed as a genuine wallet response, notification, token, spending record, or quote, corrupting wallet state or driving the application to act on forged data. The fix verifies the event kind, id, signature, and exact configured wallet author before decrypting or parsing the plaintext.
You are affected if you are using a version that falls within the vulnerable range and your application parses NIP-47 wallet-connect or NIP-60 wallet events received from relays.
nostr is vulnerable to Improper Verification of Data Authenticity in versions 0.0.1 - 0.44.6.
Upgrade the nostr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant