High severity7.5NVD Advisory· Published Jul 30, 2020· Updated Jun 17, 2026
CVE-2020-15130
CVE-2020-15130
Description
In SLPJS (npm package slpjs) before version 0.27.4, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group token type as is required by the NFT1 specification. This is fixed in version 0.27.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
slpjsnpm | < 0.27.4 | 0.27.4 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/simpleledger/slpjs/commit/290c20e8bff13ac81459d43e54cac232b5e3456cnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-cc2p-4jhr-xhhxghsaADVISORY
- github.com/simpleledger/slpjs/security/advisories/GHSA-cc2p-4jhr-xhhxnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-15130ghsaADVISORY
News mentions
0No linked articles in our index yet.