Justification Verification Flaw in Go-F3 by Filecoin
CVE-2025-59941

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 September 2025

What is CVE-2025-59941?

The go-f3 implementation of Fast Finality for Filecoin has a vulnerability in its justification verification caching mechanism. In versions 0.8.8 and below, the system does not adequately validate the relationship between cached justification results and their corresponding message contexts. An attacker is able to exploit this flaw by submitting a valid message with an appropriate justification, which can then be reused in invalid contexts, effectively bypassing the intended verification process. This issue poses a risk to the integrity of validations within the system and is addressed in version 0.8.9.

Affected Version(s)

go-f3 < 0.8.9

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59941 : Justification Verification Flaw in Go-F3 by Filecoin