Holder can generate proof of ownership for credentials it does not control in vp-toolkit
- Severity:
- High
Description
The verifyVerifiablePresentation() method check the cryptographic integrity of the Verifiable Presentation, but it does not check if the credentialSubject.id DID matches the signer of the VP proof.
The verifier is impacted by this vulnerability.
Recommendation
Update the vp-toolkit package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.2.2
- Patched version(s): 0.2.2
References
Related Issues
- Holder can (re)create authentic credentials after receiving a credential in vp-toolkit - Vulnerability
- Flowise does not Prevent Bypass of Password Confirmation - Unverified Password Change - Vulnerability
- Axios: Nested axios option objects can consume polluted prototype values - Vulnerability
- Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials) - Vulnerability
You might also like:
- Tags:
- npm
- vp-toolkit
Anything's wrong? Let us know Last updated on January 09, 2023


