Description
Versions of msrcrypto prior to 1.4.1 are vulnerable to Sensitive Data Exposure. The package’s Elliptic Curve Cryptography (ECC) implementation may leak information about a server’s private ECC key. It can also allow attackers to craft invalid ECDSA signatures that pass as valid. There is no published proof-of-concept for this vulnerability.
Recommendation
Update the msrcrypto package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.4.1
- Patched version(s): 1.4.1
References
Could your website be exposed too?
SmartScanner can check your website for Sensitive Data Exposure in msrcrypto and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Sensitive data exposure in NATS - CVE-2020-26149
- Sensitive data exposure in NATS - nats - CVE-2020-26149
- Converse.js Exposure of Sensitive Information - CVE-2018-6591
- @kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor - CVE-2026-8766


