In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade nostr-relay-pool to version 0.44.2 or higher.
Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity in the cache process. An attacker can compromise the integrity of stored event data by injecting arbitrary events without valid signatures into the application's trusted database, enabling impersonation of any public key or corruption of application state derived from stored events. This is only exploitable if the application connects to untrusted or compromised relays and persists received events.