Vulnerability library
Security checkMarch 25, 2026

sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmsjcl

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

All versions of the package sjcl are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim’s ECDH private key by sending crafted off-curve public keys and observing ECDH outputs.

Recommendation

Update the sjcl package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 1.0.8
  • Patched version(s): 1.0.9

References

Could your website be exposed too?

SmartScanner can check your website for sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated March 25, 2026