@nfid/embed has compromised private key due to @dfinity/auth-client producing insecure session keys
- Severity:
- High
Description
User sessions in the @nfid/embed SDK with Ed25519 keys are vulnerable due to a compromised private key 535yc-uxytb-gfk7h-tny7p-vjkoe-i4krp-3qmcl-uqfgr-cpgej-yqtjq-rqe. This exposes users to potential loss of funds on ledgers and unauthorized access to canisters they control.
Recommendation
Update the @nfid/embed package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.10.0, < 0.10.1-alpha.6
- Patched version(s): 0.10.1-alpha.6
References
Related Issues
- @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtrack - CVE-2025-25289
- agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate` - @dfinity/identity - CVE-2024-1631
- @octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking - CVE-2025-25285
- Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string) - Vulnerability
You might also like:
- Tags:
- npm
- @nfid/embed
Anything's wrong? Let us know Last updated on March 15, 2026


