Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.6 Node.js & npm GHSA-36f9-7rg5-cpf8 CVE-2026-56744

BSV Wallet Toolbox Packages Vulnerable to Output Script Substitution, Enabling Fund Redirection

A flaw in @bsv/wallet-toolbox, @bsv/wallet-toolbox-client, and @bsv/wallet-toolbox-mobile allows a malicious or compromised remote storage provider to substitute transaction recipient scripts, causing wallets to sign and broadcast transactions that redirect funds while the UI still shows the intended recipient. Fixed in version 2.4.0.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A vulnerability has been disclosed in `@bsv/wallet-toolbox`, `@bsv/wallet-toolbox-client`, and `@bsv/wallet-toolbox-mobile`, npm packages that provide BRC-100 wallet signing and storage components for Bitcoin SV applications. The issue allows a remote storage provider involved in transaction creation to tamper with transaction outputs in a way that is invisible to the wallet application and end user, potentially leading to redirected funds. The issue is tracked as CVE-2026-56744 and GHSA-36f9-7rg5-cpf8. [Source: 3958, 25818]

What happened

Security researchers identified that transactions created through a remote `StorageClient` in the affected packages trust output locking scripts returned by the storage provider without verifying that they match the outputs originally requested by the caller. This means a storage provider that is malicious, or has been compromised, can substitute a different recipient script or inject an additional output into a transaction before it is signed. The wallet application and its user interface continue to display the originally intended recipient, so the substitution is not visible to the user at the time of signing or broadcasting.

Technical cause

The root cause is classified as Improper Validation of Consistency within Input (CWE-1288). When a wallet constructs a transaction via a remote `StorageClient`, the storage provider supplies output locking scripts as part of the transaction data. The affected code does not cross-check these storage-supplied scripts and values against the outputs the caller originally requested before the wallet signs the transaction. As a result, any discrepancy introduced by the storage provider passes through unchecked.

Why it matters

Because the substitution happens at the storage layer and is not reflected in the application's displayed recipient, a user or application has no visual indication that a transaction has been altered before signing. If exploited, this allows a malicious or compromised storage provider to redirect funds to an attacker-controlled destination instead of the intended recipient, undermining a core guarantee of wallet software: that what is shown to the user is what gets signed and broadcast.

Who is affected

Applications and services that use `@bsv/wallet-toolbox`, `@bsv/wallet-toolbox-client`, or `@bsv/wallet-toolbox-mobile` together with a remote `StorageClient` provider for transaction construction are affected. Applications relying solely on local storage for transaction construction are not described as vulnerable in the available facts.

Affected versions

`@bsv/wallet-toolbox` and `@bsv/wallet-toolbox-client`: versions from 1.1.47 up to but not including 2.4.0. `@bsv/wallet-toolbox-mobile`: versions from its initial release 1.3.21 up to but not including 2.4.0. Public source material also references version 2.3.3 as being within the affected range for all three packages.

Fixes and mitigation

All three packages are patched in version 2.4.0. Organizations that cannot upgrade immediately should avoid using remote `StorageClient` providers, switch to local storage for transaction construction, or independently verify every transaction output's locking script and value against the original request before the wallet signs it.

Recommended action

Upgrade `@bsv/wallet-toolbox`, `@bsv/wallet-toolbox-client`, and `@bsv/wallet-toolbox-mobile` to version 2.4.0 as soon as possible. If an immediate upgrade is not feasible, disable or replace remote `StorageClient` providers with local storage, or add independent verification of all transaction outputs before signing, as described in the advisory.

PatchBriefing score

5.6 / 10 · Medium

Official CVSS: 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

The Patchwire score of 5.6 reflects a CVSS base score of 8.7, driven primarily by the high impact on integrity (funds can be redirected) with no reported impact on confidentiality or availability. The vector indicates the issue can be triggered over the network with low attack complexity, no privileges required, and no user interaction, which adds modest additional weight to the score. There is no evidence of known exploitation or public exploit code, and no EPSS score is available, which limits the overall score despite the high base severity. A fix is available, which also constrains the final score relative to unpatched, actively exploited issues.

Affected versions

@bsv/wallet-toolbox >= 1.1.47, < 2.4.0
vulnerable
≥ 2.4.0
patched
@bsv/wallet-toolbox-client >= 1.1.47, < 2.4.0
vulnerable
≥ 2.4.0
patched
@bsv/wallet-toolbox-mobile >= 1.3.21, < 2.4.0
vulnerable
≥ 2.4.0
patched

Reported fixes

All three packages are patched in version 2.4.0. Organizations that cannot upgrade immediately should avoid using remote `StorageClient` providers, switch to local storage for transaction construction, or independently verify every transaction output's locking script and value against the original request before the wallet signs it.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
BSV Wallet Toolbox Packages Vulnerable to Output Script Substitution, Enabling Fund Redirection
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email