High severity7.5NVD Advisory· Published May 21, 2023· Updated Jun 17, 2026
CVE-2023-33252
CVE-2023-33252
Description
iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
snarkjsnpm | <= 0.6.11 | — |
Affected products
3- snarkjs/snarkjsdescription
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-xp5g-jhg3-3rg2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-33252ghsaADVISORY
- github.com/iden3/snarkjs/commits/master/src/groth16_verify.jsnvdProductWEB
- github.com/iden3/snarkjs/tagsnvdProductWEB
News mentions
0No linked articles in our index yet.