Holder can (re)create authentic credentials after receiving a credential in vp-toolkit
- Severity:
- High
Description
The verifyVerifiableCredential() method check the cryptographic integrity of the Verifiable Credential, but it does not check if the credential.issuer DID matches the signer of the credential.
The verifier is impacted by this vulnerability.
Recommendation
Update the vp-toolkit package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.2.2
- Patched version(s): 0.2.2
References
Related Issues
- Holder can generate proof of ownership for credentials it does not control in vp-toolkit - Vulnerability
- Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning - Vulnerability
- devalue `uneval`ed code can create objects with polluted prototypes when `eval`ed - Vulnerability
- Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry - CVE-2026-59891
You might also like:
- Tags:
- npm
- vp-toolkit
Anything's wrong? Let us know Last updated on January 09, 2023


