Medium · 5.6 Node.js & npm GHSA-36f9-7rg5-cpf8 CVE-2026-56744
BSV Wallet Toolbox Packages Vulnerable to Output Script Substitution, Enabling Fund Redirection
A flaw in @bsv/wallet-toolbox, @bsv/wallet-toolbox-client, and @bsv/wallet-toolbox-mobile allows a malicious or compromised remote storage provider to substitute transaction recipient scripts, causing wallets to sign and broadcast transactions that redirect funds while the UI still shows the intended recipient. Fixed in version 2.4.0.
AI summary
A vulnerability has been disclosed in `@bsv/wallet-toolbox`, `@bsv/wallet-toolbox-client`, and `@bsv/wallet-toolbox-mobile`, npm packages that provide BRC-100 wallet signing and storage components for Bitcoin SV applications. The issue allows a remote storage provider involved in transaction creation to tamper with transaction outputs in a way that is invisible to the wallet application and end user, potentially leading to redirected funds. The issue is tracked as CVE-2026-56744 and GHSA-36f9-7rg5-cpf8. [Source: 3958, 25818]
What happened
Security researchers identified that transactions created through a remote `StorageClient` in the affected packages trust output locking scripts returned by the storage provider without verifying that they match the outputs originally requested by the caller. This means a storage provider that is malicious, or has been compromised, can substitute a different recipient script or inject an additional output into a transaction before it is signed. The wallet application and its user interface continue to display the originally intended recipient, so the substitution is not visible to the user at the time of signing or broadcasting.
Technical cause
The root cause is classified as Improper Validation of Consistency within Input (CWE-1288). When a wallet constructs a transaction via a remote `StorageClient`, the storage provider supplies output locking scripts as part of the transaction data. The affected code does not cross-check these storage-supplied scripts and values against the outputs the caller originally requested before the wallet signs the transaction. As a result, any discrepancy introduced by the storage provider passes through unchecked.
Why it matters
Because the substitution happens at the storage layer and is not reflected in the application's displayed recipient, a user or application has no visual indication that a transaction has been altered before signing. If exploited, this allows a malicious or compromised storage provider to redirect funds to an attacker-controlled destination instead of the intended recipient, undermining a core guarantee of wallet software: that what is shown to the user is what gets signed and broadcast.
Who is affected
Applications and services that use `@bsv/wallet-toolbox`, `@bsv/wallet-toolbox-client`, or `@bsv/wallet-toolbox-mobile` together with a remote `StorageClient` provider for transaction construction are affected. Applications relying solely on local storage for transaction construction are not described as vulnerable in the available facts.
Affected versions
`@bsv/wallet-toolbox` and `@bsv/wallet-toolbox-client`: versions from 1.1.47 up to but not including 2.4.0. `@bsv/wallet-toolbox-mobile`: versions from its initial release 1.3.21 up to but not including 2.4.0. Public source material also references version 2.3.3 as being within the affected range for all three packages.
Fixes and mitigation
All three packages are patched in version 2.4.0. Organizations that cannot upgrade immediately should avoid using remote `StorageClient` providers, switch to local storage for transaction construction, or independently verify every transaction output's locking script and value against the original request before the wallet signs it.
Recommended action
Upgrade `@bsv/wallet-toolbox`, `@bsv/wallet-toolbox-client`, and `@bsv/wallet-toolbox-mobile` to version 2.4.0 as soon as possible. If an immediate upgrade is not feasible, disable or replace remote `StorageClient` providers with local storage, or add independent verification of all transaction outputs before signing, as described in the advisory.
PatchBriefing score
5.6 / 10 · Medium
Official CVSS: 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
The Patchwire score of 5.6 reflects a CVSS base score of 8.7, driven primarily by the high impact on integrity (funds can be redirected) with no reported impact on confidentiality or availability. The vector indicates the issue can be triggered over the network with low attack complexity, no privileges required, and no user interaction, which adds modest additional weight to the score. There is no evidence of known exploitation or public exploit code, and no EPSS score is available, which limits the overall score despite the high base severity. A fix is available, which also constrains the final score relative to unpatched, actively exploited issues.
Affected versions
- @bsv/wallet-toolbox >= 1.1.47, < 2.4.0
- vulnerable
- ≥ 2.4.0
- patched
- @bsv/wallet-toolbox-client >= 1.1.47, < 2.4.0
- vulnerable
- ≥ 2.4.0
- patched
- @bsv/wallet-toolbox-mobile >= 1.3.21, < 2.4.0
- vulnerable
- ≥ 2.4.0
- patched
Reported fixes
All three packages are patched in version 2.4.0. Organizations that cannot upgrade immediately should avoid using remote `StorageClient` providers, switch to local storage for transaction construction, or independently verify every transaction output's locking script and value against the original request before the wallet signs it.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email