VDB
Sign up
HIGH7.5

GHSA-qv7w-v773-3xqm

sm-crypto Affected by Signature Malleability in SM2-DSA

Quick fix

GHSA-qv7w-v773-3xqm — sm-crypto: upgrade to the fixed version with the command below.

npm install sm-crypto@0.3.14

Details

### Summary

A signature malleability vulnerability exists in the SM2 signature verification logic of the sm-crypto library. An attacker can derive a new valid signature for a previously signed message from an existing signature.

### Credit

This vulnerability was discovered by: - XlabAI Team of Tencent Xuanwu Lab - Atuin Automated Vulnerability Discovery Engine

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sm-crypto
Introduced in: 0Fixed in: 0.3.14
Fixnpm install sm-crypto@0.3.14

References