Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-56744— `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction (can redirect payments when using remote storage)

Quick assessment

Affected
bsv-blockchain @bsv/wallet-toolbox
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

提供了 BRC-100 钱包的签名和存储组件,而 和 则为基于标准平台和移动平台的应用程序提供了面向客户端的分发版本,这些应用程序使用钱包存储服务。这些软件包中存在一个漏洞,导致通过远程 创建的交易,会无条件信任存储提供者返回的输出锁定脚本(output locking scripts),而不会验证这些脚本是否与调用方所请求的输出一致。恶意或已被攻陷的存储提供者可以替换收款脚本或注入额外的输出,从而使得钱包在应用和用户界面仍显示预期收款方的情况下,签署并广播一个将资金重定向的交易。 根据源码及 npm 发布历史记录

CVSS 8.7 · High EPSS 0.30% · P21

Affected Version Matrix 3

VendorProduct Version RangeStatus
bsv-blockchain @bsv/wallet-toolbox >= 1.1.47, < 2.4.0 affected
bsv-blockchain @bsv/wallet-toolbox-client >= 1.1.47, < 2.4.0 affected
bsv-blockchain @bsv/wallet-toolbox-mobile >= 1.3.21, < 2.4.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-56744

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
`@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction (can redirect payments when using remote storage)
Source: CVE Program / CVE List V5
Vulnerability Description
`@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet storage services. A vulnerability in these packages causes transactions created through a remote `StorageClient` to trust output locking scripts returned by the storage provider without verifying that they match the outputs requested by the caller. A malicious or compromised storage provider can substitute a recipient script or inject an additional output, causing the wallet to sign and broadcast a transaction that redirects funds while the application and user interface continue to display the intended recipient. Source and npm publication history indicate that stable versions `@bsv/wallet-toolbox` and `@bsv/wallet-toolbox-client` from 1.1.47 through 2.3.3, and `@bsv/wallet-toolbox-mobile` from its initial 1.3.21 release through 2.3.3, are affected. All three packages are patched in version 2.4.0. Applications unable to upgrade should avoid remote `StorageClient` providers, use local storage, or independently verify every transaction output’s locking script and value against the original request before signing
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1288
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
bsv-blockchain @bsv/wallet-toolbox >= 1.1.47, < 2.4.0 -
bsv-blockchain @bsv/wallet-toolbox-client >= 1.1.47, < 2.4.0 -
bsv-blockchain @bsv/wallet-toolbox-mobile >= 1.3.21, < 2.4.0 -

II. Public POCs for CVE-2026-56744

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56744

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-56744 (4)

Vendor Advisories for CVE-2026-56744 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-56744

No comments yet


Leave a comment