Vulnerabilities/

sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey

Severity:
High

Description

All versions of the package sjcl are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim’s ECDH private key by sending crafted off-curve public keys and observing ECDH outputs.

Recommendation

Update the sjcl package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
sjcl
Anything's wrong? Let us know Last updated on March 25, 2026