VDB
Sign up
CRITICAL9.1

GHSA-pgx9-497m-6c4v

sm-crypto Affected by Private Key Recovery in SM2-PKE

Quick fix

GHSA-pgx9-497m-6c4v — sm-crypto: upgrade to the fixed version with the command below.

npm install sm-crypto@0.3.14

Details

### Summary

A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto. By interacting with the SM2 decryption interface multiple times, an attacker can fully recover the private key within approximately several hundred interactions.

### Credit

This vulnerability was discovered by: - XlabAI Team of Tencent Xuanwu Lab - Atuin Automated Vulnerability Discovery Engine

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sm-crypto
Introduced in: 0Fixed in: 0.3.14
Fixnpm install sm-crypto@0.3.14

References