npm package report

Is altcha-lib safe?

1 known vulnerability, worst severity MEDIUM.

cvss
6.5

how bad it is if exploited, out of 10

epss
0.50%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-6gvq-jcmp-8959, the advisory selected below

// advisories

GHSA-6gvq-jcmp-8959

MEDIUMCVE-2025-68113

A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay attacks. The HMAC signature does not unambiguously bind challenge parameters to the nonce, allowing an attacker to reinterpret a valid proof-of-work submission with a modified expiration value. This may allow previously solved challenges to be reused beyond their intended lifetime,

Affected
>=0, <1.0.0
Fixed in
1.4.1
Weakness
CWE-115
Published
2025-12-16
Source
github

GHSANVDMITRE


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 02:35 UTC. The most recent advisory here was published 2025-12-16. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is altcha-lib safe? npm package security report | CyberXYZ