GHSA-84c3-j8r2-mcm8
UNKNOWNUser sessions in the @nfid/embed SDK with Ed25519 keys are vulnerable due to a compromised private key 535yc-uxytb-gfk7h-tny7p-vjkoe-i4krp-3qmcl-uqfgr-cpgej-yqtjq-rqe. This exposes users to potential loss of funds on ledgers and unauthorized access to canisters they control.
- Affected
- >=0.10.0, <0.10.1-alpha.6
- Fixed in
- not stated
- Weakness
- CWE-321
- Published
- 2024-02-26
- Source
- osv