Vulnerability CVE-2023-33252


Published: 2023-05-21   Modified: 2023-05-22

Description:
iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.

 References:
https://github.com/iden3/snarkjs/commits/master/src/groth16_verify.js
https://github.com/iden3/snarkjs/tags

Copyright 2026, cxsecurity.com

 

Back to Top