VDB
Sign up
MEDIUM5.7

GHSA-wmx6-vxcf-c3gr

Validation Bypass in slp-validate

Quick fix

GHSA-wmx6-vxcf-c3gr — slp-validate: upgrade to the fixed version with the command below.

npm install slp-validate@1.0.1

Details

Versions of `slp-validate` prior to 1.0.1 are vulnerable to a validation bypass. Bitcoin scripts may cause the validation result from `slp-validate` to differ from the specified SLP consensus. This allows an attacker to create a Bitcoin script that causes a hard-fork from the SLP consensus.

## Recommendation

Upgrade to version 1.0.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/slp-validate
Introduced in: 1.0.0Fixed in: 1.0.1
Fixnpm install slp-validate@1.0.1

References