npm package report

Is @libp2p/peer-store safe?

1 known vulnerability, worst severity HIGH.

cvss
8.2

how bad it is if exploited, out of 10

epss
0.20%

chance of exploitation in the next 30 days

xyz score
3.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-vrf4-mx87-p53w, the advisory selected below

// advisories

GHSA-vrf4-mx87-p53w

HIGHCVE-2026-86039

@libp2p/peer-store accepts a signed PeerRecord whose envelope is signed by one peer but whose payload claims a different peer ID. The vulnerable consumePeerRecord path verifies the envelope signature, but does not verify that the envelope signer is the same peer as the wrapped PeerRecord.peerId. As a result, an attacker can sign a record with their own key while placing a victim peer ID in the pay

Affected
>= 8.0.0, < 12.0.24
Fixed in
12.0.24
Weakness
CWE-290
Published
2026-09-17
Source
github

GHSANVDMITREreferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 02:39 UTC. The most recent advisory here was published 2026-09-17. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @libp2p/peer-store safe? npm package security report | CyberXYZ