PT-2026-94370 · Npm · @Libp2P/Peer-Store
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
@libp2p/peer-store versions 8.0.0 through 12.0.23
Description
In the
@libp2p/peer-store component, the consumePeerRecord() function verifies a RecordEnvelope signature but fails to ensure that the PeerRecord.peerId within the signed payload matches the signer peer ID derived by RecordEnvelope.openAndCertify(). Because the expectedPeer option only validates the envelope signer, an attacker can sign a record with their own key while including a victim's peer ID and attacker-controlled multiaddrs in the payload.This allows an attacker to store certified addresses for a victim peer, leading to address-book corruption, routing manipulation, reachability disruption, or dial redirection and failure. However, this does not allow a full identity takeover as the connection upgrade process still verifies the remote peer identity.
Recommendations
Update @libp2p/peer-store to version 12.0.24.
Exploit
Fix
Insufficient Verification of Data Authenticity
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Libp2P/Peer-Store