CRITICAL9.1
GHSA-pgx9-497m-6c4v
sm-crypto Affected by Private Key Recovery in SM2-PKE
Quick fix
GHSA-pgx9-497m-6c4v — sm-crypto: upgrade to the fixed version with the command below.
npm install sm-crypto@0.3.14Details
### Summary
A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto. By interacting with the SM2 decryption interface multiple times, an attacker can fully recover the private key within approximately several hundred interactions.
### Credit
This vulnerability was discovered by: - XlabAI Team of Tencent Xuanwu Lab - Atuin Automated Vulnerability Discovery Engine
Are you affected?
Enter the version of the package you're using.