Vulnerabilities/

Holder can (re)create authentic credentials after receiving a credential in vp-toolkit

Severity:
High

Description

The verifyVerifiableCredential() method check the cryptographic integrity of the Verifiable Credential, but it does not check if the credential.issuer DID matches the signer of the credential.

The verifier is impacted by this vulnerability.

Recommendation

Update the vp-toolkit package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vp-toolkit
Anything's wrong? Let us know Last updated on January 09, 2023