VYPR

crates.io package

risc0-zkvm

pkg:cargo/risc0-zkvm

Vulnerabilities (3)

  • CVE-2025-61588CriOct 2, 2025
    affected < 2.3.2fixed 2.3.2

    RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a crafted response to write to an arbitrary mem

  • CVE-2025-54873LowAug 6, 2025
    affected >= 2.0.0, < 2.2.0fixed 2.2.0

    RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. RISC packages risc0-zkvm versions 2.0.0 through 2.1.0 and risc0-circuit-rv32im and risc0-circuit-rv32im-sys versions 2.0.0 through 2.0.4 contain vulnerabilitie

  • CVE-2025-52484LowJun 20, 2025
    affected >= 2.0.0, < 2.1.0fixed 2.1.0

    RISC Zero is a general computing platform based on zk-STARKs and the RISC-V microarchitecture. Due to a missing constraint in the rv32im circuit, any 3-register RISC-V instruction (including remu and divu) in risc0-zkvm 2.0.0, 2.0.1, and 2.0.2 are vulnerable to an attack by a mal