Remote Script Trusting Vulnerability in BSV Wallet Toolbox by BSV Blockchain
CVE-2026-56744

8.7HIGH

What is CVE-2026-56744?

A significant vulnerability exists in the BSV Wallet Toolbox and its client-focused applications, enabling a malicious storage provider to manipulate transaction outputs. This flaw arises because transactions created through a remote StorageClient do not verify the returned output locking scripts against the request. This could allow an attacker to redirect funds while the application shows the intended recipient to the user. All affected packages need urgent upgrades to version 2.4.0. Users are advised to avoid compromised remote StorageClient providers and consider local storage or rigorous independent verification of transaction outputs.

Affected Version(s)

@bsv/wallet-toolbox >= 1.1.47, < 2.4.0

@bsv/wallet-toolbox-client >= 1.1.47, < 2.4.0

@bsv/wallet-toolbox-mobile >= 1.3.21, < 2.4.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.