PT-2026-98158 · Npm · @Bsv/Wallet-Toolbox-Mobile+2
CVE-2026-56744
·
Published
2026-09-24
·
Updated
2026-09-28
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
@bsv/wallet-toolbox versions 1.1.47 through 2.3.3
@bsv/wallet-toolbox-client versions 1.1.47 through 2.3.3
@bsv/wallet-toolbox-mobile versions 1.3.21 through 2.3.3
Description
An issue exists where transactions created via a remote
StorageClient trust output locking scripts returned by the storage provider without verifying they match the outputs requested by the caller. A malicious or compromised storage provider can substitute a recipient script or inject an additional output. This allows the provider to redirect funds by causing the wallet to sign and broadcast a transaction that differs from what is displayed in the application user interface. The flaw occurs because buildSignableTransaction() uses the lockingScript from the storage response without consulting args.outputs, and WalletPermissionsManager.createAction() does not inspect the transaction outputs before signing.Recommendations
Update @bsv/wallet-toolbox to version 2.4.0.
Update @bsv/wallet-toolbox-client to version 2.4.0.
Update @bsv/wallet-toolbox-mobile to version 2.4.0.
As a temporary workaround, avoid using remote
StorageClient providers and use local storage instead.
As a temporary workaround, independently verify every transaction output locking script and value against the original request before signing.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Bsv/Wallet-Toolbox
@Bsv/Wallet-Toolbox-Client
@Bsv/Wallet-Toolbox-Mobile