Vulnerabilities/

Double spend in snarkjs

Severity:
High

Description

iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
snarkjs
Anything's wrong? Let us know Last updated on January 21, 2025

This issue is available in SmartScanner Professional

See Pricing