PatchSiren

bsv-blockchain CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH bsv-blockchain CVE published 2026-09-24

CVE-2026-56744

A vulnerability in `@bsv/wallet-toolbox`, `@bsv/wallet-toolbox-client`, and `@bsv/wallet-toolbox-mobile` causes transactions created through a remote `StorageClient` to trust output locking scripts returned by the storage provider without verification, allowing a malicious provider to redirect funds. The vulnerability affects stable versions `@bsv/wallet-toolbox` and `@bsv/wallet-toolbox-client` from 1.1. [truncated]