Vulnerabilities/

Improper Verification of Cryptographic Signature

Severity:
High

Description

The verifyWithMessage method of tEnvoyNaClSigningKey always returns true for any signature of a SHA-512 hash matching the SHA-512 hash of the message even if the signature is invalid.

Recommendation

Update the tenvoy package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tenvoy
Anything's wrong? Let us know Last updated on January 23, 2026