Intel

AIKIDO-2026-883913

agent-manifest is vulnerable to Insufficient Verification of Data Authenticity

Insufficient Verification of Data AuthenticityGHSA-85fc-3g4g-fjjc Published 2 days ago

75

High Risk

This Affects:

PYTHONagent-manifest
0.1.0 - 0.11.2
Fixed in 0.12.0
Are you affected? Scan for Free

TL;DR

The integrated verifier treats equality between a caller-supplied report hash and a locally computed manifest digest as successful hardware attestation. A party holding a validly signed manifest can append unsigned attestation metadata with a matching hash and no real TPM or TEE evidence, and the verifier marks attestation as verified. This converts an attestation-unavailable outcome into a valid verdict and bypasses attestation enforcement. The fix requires genuine hardware appraisal rather than hash equality to mark attestation verified.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you rely on attestation enforcement in the integrated verifier.

Background info

agent-manifest is vulnerable to Insufficient Verification of Data Authenticity in versions 0.1.0 - 0.11.2.

How to fix this

Upgrade the agent-manifest library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform