cryptoadvance.specter@1.2.1 vulnerabilities

A GUI for Bitcoin Core & Electrum optimised to work with airgapped hardware wallets

Direct Vulnerabilities

Known vulnerabilities in the cryptoadvance.specter package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Open Redirect

cryptoadvance.specter is an A GUI for Bitcoin Core & Electrum optimised to work with airgapped hardware wallets

Affected versions of this package are vulnerable to Open Redirect where the "next" parameter during the login process on Specter desktop can be manipulated to redirect users to an unauthorized domain after login. This vulnerability poses a phishing risk, as attackers can easily direct users to malicious sites by altering the "next" parameter in the URL.

How to fix Open Redirect?

Upgrade cryptoadvance.specter to version 2.0.2 or higher.

[,2.0.2)
  • M
Cross-site Request Forgery (CSRF)

cryptoadvance.specter is an A GUI for Bitcoin Core & Electrum optimised to work with airgapped hardware wallets

Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) when /toggle_hide_sensitive_info endpoint got called.

How to fix Cross-site Request Forgery (CSRF)?

Upgrade cryptoadvance.specter to version 1.7.2 or higher.

[,1.7.2)