Insufficient Verification of Data Authenticity in sigstore-js
Fixed in: @sigstore/verify 3.1.1
details
- Finding IDs
- F-SIG-JS-TLOGTIME-001
- CVE
- CVE-2026-48816
- GHSA
- GHSA-xgjw-pm74-86q4
- Status
- patched
- CWE
- CWE-345
- Fixed in
- @sigstore/verify 3.1.1
- Recorded credit
- reporter: @1seal
- Note
- GHSA-xgjw-pm74-86q4; inclusionProof-only bundle integratedTime was treated as a trusted timestamp without cryptographic binding.
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Insufficient Verification of Data Authenticity in sigstore-js
- Upstream CWE
- CWE-345
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-SIG-JS-TLOGTIME-001: Verification failures. An unsigned integratedTime influences certificate-time validation. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-SIG-JS-TLOGTIME-001
Security area (1seal assessment): Integrity. An unauthenticated integratedTime is used as trusted time evidence; the affected property is integrity of the timestamp used for verification. Reviewed 24 Sep 2026.