Vulnerabilities/

tiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled envir

Severity:
High

Description

Private key can be extracted on signing a malicious JSON-stringifiable object, when global Buffer is buffer package

Recommendation

Update the tiny-secp256k1 package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tiny-secp256k1
Anything's wrong? Let us know Last updated on July 01, 2025