Justification Verification Flaw in Go-F3 by Filecoin
CVE-2025-59941
5.9MEDIUM
What is CVE-2025-59941?
The go-f3 implementation of Fast Finality for Filecoin has a vulnerability in its justification verification caching mechanism. In versions 0.8.8 and below, the system does not adequately validate the relationship between cached justification results and their corresponding message contexts. An attacker is able to exploit this flaw by submitting a valid message with an appropriate justification, which can then be reused in invalid contexts, effectively bypassing the intended verification process. This issue poses a risk to the integrity of validations within the system and is addressed in version 0.8.9.
Affected Version(s)
go-f3 < 0.8.9