Npm · @Libp2P/Peer-Store · CVE-2026-86039
**Name of the Vulnerable Software and Affected Versions**
@libp2p/peer-store versions 8.0.0 through 12.0.23
**Description**
In the `@libp2p/peer-store` component, the `consumePeerRecord()` function verifies a `RecordEnvelope` signature but fails to ensure that the `PeerRecord.peerId` within the signed payload matches the signer peer ID derived by `RecordEnvelope.openAndCertify()`. Because the `expectedPeer` option only validates the envelope signer, an attacker can sign a record with their own key while including a victim's peer ID and attacker-controlled multiaddrs in the payload.
This allows an attacker to store certified addresses for a victim peer, leading to address-book corruption, routing manipulation, reachability disruption, or dial redirection and failure. However, this does not allow a full identity takeover as the connection upgrade process still verifies the remote peer identity.
**Recommendations**
Update @libp2p/peer-store to version 12.0.24.