PT-2026-98158 · Npm · @Bsv/Wallet-Toolbox-Mobile+2

CVE-2026-56744

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions @bsv/wallet-toolbox versions 1.1.47 through 2.3.3 @bsv/wallet-toolbox-client versions 1.1.47 through 2.3.3 @bsv/wallet-toolbox-mobile versions 1.3.21 through 2.3.3
Description An issue exists where transactions created via a remote StorageClient trust output locking scripts returned by the storage provider without verifying they match the outputs requested by the caller. A malicious or compromised storage provider can substitute a recipient script or inject an additional output. This allows the provider to redirect funds by causing the wallet to sign and broadcast a transaction that differs from what is displayed in the application user interface. The flaw occurs because buildSignableTransaction() uses the lockingScript from the storage response without consulting args.outputs, and WalletPermissionsManager.createAction() does not inspect the transaction outputs before signing.
Recommendations Update @bsv/wallet-toolbox to version 2.4.0. Update @bsv/wallet-toolbox-client to version 2.4.0. Update @bsv/wallet-toolbox-mobile to version 2.4.0. As a temporary workaround, avoid using remote StorageClient providers and use local storage instead. As a temporary workaround, independently verify every transaction output locking script and value against the original request before signing.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56744
GHSA-36F9-7RG5-CPF8

Affected Products

@Bsv/Wallet-Toolbox
@Bsv/Wallet-Toolbox-Client
@Bsv/Wallet-Toolbox-Mobile