@libp2p/peer-store is vulnerable to Authentication Bypass by Spoofing
82
High Risk
consumePeerRecord verifies a PeerRecord envelope signature but does not check that the signer matches the peer id in the payload. A record signed by one peer can therefore store certified multiaddrs under another peer's id, which are preferred when dialing. The fix requires the envelope signer to match the record peer id before storing those addresses.
You are affected if you are using a version that falls within the vulnerable range and you ingest signed PeerRecord envelopes from the network, including via gossipsub peer exchange. Nodes that only consume locally generated peer records are not exposed.
@libp2p/peer-store is vulnerable to Authentication Bypass by Spoofing in versions 8.0.0 - 12.0.23.
Upgrade the @libp2p/peer-store library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant