CVE-2026-56744
Last modified
CVE-2026-56744 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet storage services. A vulnerability in these packages causes transactions created through a remote `StorageClient` to trust output locking scripts returned by the storage provider without verifying that they match the outputs requested by the caller.
Description
`@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet storage services. A vulnerability in these packages causes transactions created through a remote `StorageClient` to trust output locking scripts returned by the storage provider without verifying that they match the outputs requested by the caller. A malicious or compromised storage provider can substitute a recipient script or inject an additional output, causing the wallet to sign and broadcast a transaction that redirects funds while the application and user interface continue to display the intended recipient. Source and npm publication history indicate that stable versions `@bsv/wallet-toolbox` and `@bsv/wallet-toolbox-client` from 1.1.47 through 2.3.3, and `@bsv/wallet-toolbox-mobile` from its initial 1.3.21 release through 2.3.3, are affected. All three packages are patched in version 2.4.0. Applications unable to upgrade should avoid remote `StorageClient` providers, use local storage, or independently verify every transaction output’s locking script and value against the original request before signing
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| bsv-blockchain | @bsv/wallet-toolbox | >= 1.1.47, < 2.4.0 |
| bsv-blockchain | @bsv/wallet-toolbox-client | >= 1.1.47, < 2.4.0 |
| bsv-blockchain | @bsv/wallet-toolbox-mobile | >= 1.3.21, < 2.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-56744?
How severe is CVE-2026-56744?
How do I fix CVE-2026-56744?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-56739Logto is the modern, open-source auth infrastructure for Saa…8.5
- CVE-2026-5674A flaw was found in PipeWire, a multimedia server. This vuln…8.8
- CVE-2026-56740JLine is a Java library for handling console input. Prior to…7.5
- CVE-2026-56741JLine is a Java library for handling console input. Prior to…7.5
- CVE-2026-56742Cilium is a networking, observability, and security solution…8.9
- CVE-2026-56743Cilium is a networking, observability, and security solution…5.4
- CVE-2026-56745Netty is a network application framework for development of …7.5
- CVE-2026-56746Netty is a network application framework for development of …6.5
- CVE-2026-56747Improper control of generation of code in the JSON Pointer-t…8.8
- CVE-2026-56748Improper validation of symbolic links in the Pack Git import…8.8
- CVE-2026-5675A vulnerability was found in itsourcecode Construction Manag…6.3
- CVE-2026-56750Gitea Remember-Me Token Theft Not Invalidating Attacker Sess…9.1
Are you affected by CVE-2026-56744?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
