PT-2026-94370 · Npm · @Libp2P/Peer-Store

·

CVE-2026-86039

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions @libp2p/peer-store versions 8.0.0 through 12.0.23
Description In the @libp2p/peer-store component, the consumePeerRecord() function verifies a RecordEnvelope signature but fails to ensure that the PeerRecord.peerId within the signed payload matches the signer peer ID derived by RecordEnvelope.openAndCertify(). Because the expectedPeer option only validates the envelope signer, an attacker can sign a record with their own key while including a victim's peer ID and attacker-controlled multiaddrs in the payload.
This allows an attacker to store certified addresses for a victim peer, leading to address-book corruption, routing manipulation, reachability disruption, or dial redirection and failure. However, this does not allow a full identity takeover as the connection upgrade process still verifies the remote peer identity.
Recommendations Update @libp2p/peer-store to version 12.0.24.

Exploit

Fix

Insufficient Verification of Data Authenticity

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86039
GHSA-VRF4-MX87-P53W

Affected Products

@Libp2P/Peer-Store