High severity7.5NVD Advisory· Published Jul 30, 2020· Updated Jun 17, 2026
CVE-2020-15131
CVE-2020-15131
Description
In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group token type as is required by the NFT1 specification. This is fixed in version 1.2.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
slp-validatenpm | < 1.2.2 | 1.2.2 |
Affected products
3cpe:2.3:a:simpleledger:slp-validate:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:simpleledger:slp-validate:*:*:*:*:*:*:*:*range: <1.2.2
- (no CPE)range: < 1.2.2
Patches
Vulnerability mechanics
References
4- github.com/simpleledger/slp-validate.js/commit/3963cf914afae69084059b82483da916d97af65cnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-6jmr-jfh7-xg3hghsaADVISORY
- github.com/simpleledger/slp-validate.js/security/advisories/GHSA-6jmr-jfh7-xg3hnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-15131ghsaADVISORY
News mentions
0No linked articles in our index yet.