Remote Script Trusting Vulnerability in BSV Wallet Toolbox by BSV Blockchain
CVE-2026-56744
What is CVE-2026-56744?
A significant vulnerability exists in the BSV Wallet Toolbox and its client-focused applications, enabling a malicious storage provider to manipulate transaction outputs. This flaw arises because transactions created through a remote StorageClient do not verify the returned output locking scripts against the request. This could allow an attacker to redirect funds while the application shows the intended recipient to the user. All affected packages need urgent upgrades to version 2.4.0. Users are advised to avoid compromised remote StorageClient providers and consider local storage or rigorous independent verification of transaction outputs.
Affected Version(s)
@bsv/wallet-toolbox >= 1.1.47, < 2.4.0
@bsv/wallet-toolbox-client >= 1.1.47, < 2.4.0
@bsv/wallet-toolbox-mobile >= 1.3.21, < 2.4.0
