agent-manifest is vulnerable to Insufficient Verification of Data Authenticity
75
High Risk
The integrated verifier treats equality between a caller-supplied report hash and a locally computed manifest digest as successful hardware attestation. A party holding a validly signed manifest can append unsigned attestation metadata with a matching hash and no real TPM or TEE evidence, and the verifier marks attestation as verified. This converts an attestation-unavailable outcome into a valid verdict and bypasses attestation enforcement. The fix requires genuine hardware appraisal rather than hash equality to mark attestation verified.
You are affected if you are using a version that falls within the vulnerable range and you rely on attestation enforcement in the integrated verifier.
agent-manifest is vulnerable to Insufficient Verification of Data Authenticity in versions 0.1.0 - 0.11.2.
Upgrade the agent-manifest library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.