HIGH
bsv-blockchain
CVE published 2026-09-24
CVE-2026-56744
A vulnerability in `@bsv/wallet-toolbox`, `@bsv/wallet-toolbox-client`, and `@bsv/wallet-toolbox-mobile` causes transactions created through a remote `StorageClient` to trust output locking scripts returned by the storage provider without verification, allowing a malicious provider to redirect funds. The vulnerability affects stable versions `@bsv/wallet-toolbox` and `@bsv/wallet-toolbox-client` from 1.1. [truncated]