Headline
GHSA-xp5g-jhg3-3rg2: Double spend in snarkjs
iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.
Double spend in snarkjs
Moderate severity GitHub Reviewed Published May 22, 2023 to the GitHub Advisory Database • Updated May 22, 2023
Related news
CVE-2023-33252: History for src/groth16_verify.js - iden3/snarkjs
iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.