GHSA-mmf8-487q-p45m
HIGHCVE-2026-31839A high-severity integrity bypass vulnerability existed in Striae's digital confirmation workflow prior to v3.0.0. Hash-only validation trusted manifest hash fields that could be modified together with package content, allowing tampered confirmation packages to pass integrity checks.
- Affected
- >= 0.9.22-0, < 3.0.0
- Fixed in
- 3.0.0
- Weakness
- CWE-327
- Published
- 2026-03-11
- Source
- github