PT-2026-94369 · Npm · @Libp2P/Gossipsub
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
@libp2p/gossipsub versions 15.0.0 through 16.0.4
Description
In the default
StrictSign policy, the validateToRawMessage() function in packages/gossipsub/src/utils/buildRawMessage.ts fails to bind the supplied public key in msg.key to the claimed author in msg.from when the author is an RSA peer ID that does not inline its public key. An unauthenticated attacker can spoof a victim's RSA peer ID by placing it in msg.from, signing the message with their own private key, and providing their own public key in msg.key. This allows the message to be accepted and propagated as if it were authored by the victim. Applications relying on message.from for authorization, accounting, moderation, reputation, or audit logging may process attacker-controlled data under false origin attribution.Recommendations
Update @libp2p/gossipsub to version 16.0.5.
Exploit
Fix
Insufficient Verification of Data Authenticity
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Libp2P/Gossipsub