MEDIUM🇬🇧 English

CVE-2025-69287

CVSS 5.4v3.1pub. 2026-02-18upd. 2026-04-15

BSV Blockchain SDK jest ujednoliconym SDK TypeScript do tworzenia skalowalnych aplikacji na blockchainie BSV. Przed wersją 2.0.0 luka kryptograficzna w implementacji uwierzytelnienia BRC-104 w SDK TypeScript powodowała niepoprawne przygotowanie danych sygnatury, co skutkowało niezgodnością sygnatury między implementacjami SDK i potencjalnymi scenariuszami obejścia uwierzytelnienia. Luka znajdowała się w pliku `Peer.ts` SDK TypeScript, konkretnie w metodach `processInitialRequest` i `processInitialResponse`, gdzie dane sygnatury są przygotowywane do wzajemnego uwierzytelnienia BRC-104. SDK TypeScript nieprawidłowo przygotowywało dane sygnatury, łącząc zakodowane w base64 ciągi nonce'ów (`message.initialNonce + sessionNonce`), a następnie dekodując połączony ciąg base64 (`base64ToBytes(concatenatedString)`), co produkowało ~32-34 bajty danych sygnatury zamiast prawidłowych 64 bajtów

Pokaż oryginał (EN)

The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version 2.0.0, a cryptographic vulnerability in the TypeScript SDK's BRC-104 authentication implementation caused incorrect signature data preparation, resulting in signature incompatibility between SDK implementations and potential authentication bypass scenarios. The vulnerability was located in the `Peer.ts` file of the TypeScript SDK, specifically in the `processInitialRequest` and `processInitialResponse` methods where signature data is prepared for BRC-104 mutual authentication. The TypeScript SDK incorrectly prepared signature data by concatenating base64-encoded nonce strings (`message.initialNonce + sessionNonce`) then decoding the concatenated base64 string (`base64ToBytes(concatenatedString)`). This produced ~32-34 bytes of signature data instead of the correct 64 bytes. BRC-104 authentication relies on cryptographic signatures to establish mutual trust between peers. When signature data preparation is incorrect, signatures generated by the TypeScript SDK don't match those expected by Go/Python SDKs; cross-implementation authentication fails; and an attacker could potentially exploit this to bypass authentication checks. The fix in version 2.0.0 ensures all SDKs now produce identical cryptographic signatures, restoring proper mutual authentication across implementations.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth Bypass
CWE
Referencje