CVE-2026-56744High· 8.7▾ Twilight`@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet stor…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
@bsv/wallet-toolbox provides BRC-100 wallet signing and storage components, while @bsv/wallet-toolbox-client and @bsv/wallet-toolbox-mobile provide client-focused distributions for standard and mobile applications using wallet storage services. A vulnerability in these packages causes transactions created through a remote StorageClient to trust output locking scripts returned by the storage provider without verifying that they match the outputs requested by the caller. A malicious or compromised storage provider can substitute a recipient script or inject an additional output, causing the wallet to sign and broadcast a transaction that redirects funds while the application and user interface continue to display the intended recipient. Source and npm publication history indicate that stable versions @bsv/wallet-toolbox and @bsv/wallet-toolbox-client from 1.1.47 through 2.3.3, and @bsv/wallet-toolbox-mobile from its initial 1.3.21 release through 2.3.3, are affected. All three packages are patched in version 2.4.0. Applications unable to upgrade should avoid remote StorageClient providers, use local storage, or independently verify every transaction output’s locking script and value against the original request before signing
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
@bsv/wallet-toolbox >= 1.1.47, < 2.4.0@bsv/wallet-toolbox-client >= 1.1.47, < 2.4.0@bsv/wallet-toolbox-mobile >= 1.3.21, < 2.4.0Patched in:
@bsv/wallet-toolbox 2.4.0@bsv/wallet-toolbox-client 2.4.0@bsv/wallet-toolbox-mobile 2.4.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89584High· 7.0kernel: block: validate user space vectors during extraction (CVE-2026-89584)
CVE-2026-46117High· 7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() Sashiko points out that the user can specify WQs sharing the same CQ as a part of the uAPI and …
CVE-2026-69793High· 7.5Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-18238Medium· 5.0The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers
CVE-2026-18209Low· 3.4A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows
CVE-2026-42982High· 7.8Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.