@bsv/sdk@1.10.3 vulnerabilities

BSV Blockchain Software Development Kit

  • latest version

    2.0.5

  • latest non vulnerable version

  • first published

    2 years ago

  • latest version published

    2 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @bsv/sdk package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Following of Specification by Caller

    @bsv/sdk is a BSV Blockchain Software Development Kit

    Affected versions of this package are vulnerable to Improper Following of Specification by Caller in the Peer class, used by the processInitialRequest and processInitialResponse methods. An attacker can cause a signature to be insufficiently validated, which may lead to incompatibility with other SDK implementations using mutual BRC-104 authentication. When the affected methods prepare signatures, they concatenate nonce strings before encoding, thus losing entropy, compared to the protocol specification and to other implementations.

    How to fix Improper Following of Specification by Caller?

    Upgrade @bsv/sdk to version 2.0.0 or higher.

    <2.0.0