Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
- Severity:
- High
Description
This is a credential-exposure / credential-confusion issue.
Recommendation
Update the @sigstore/oci package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.7.1
- Patched version(s): 0.7.1
References
Related Issues
- seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization - CVE-2026-59940
- PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `f - CVE-2026-69153
- PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments - CVE-2026-45623
- Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter - CVE-2026-44487
You might also like:
- Tags:
- npm
- @sigstore/oci
Anything's wrong? Let us know Last updated on July 21, 2026


