🔐 CVE Alert

CVE-2026-56744

UNKNOWN 0.0

`@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction (can redirect payments when using remote storage)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

`@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet storage services. A vulnerability in these packages causes transactions created through a remote `StorageClient` to trust output locking scripts returned by the storage provider without verifying that they match the outputs requested by the caller. A malicious or compromised storage provider can substitute a recipient script or inject an additional output, causing the wallet to sign and broadcast a transaction that redirects funds while the application and user interface continue to display the intended recipient. Source and npm publication history indicate that stable versions `@bsv/wallet-toolbox` and `@bsv/wallet-toolbox-client` from 1.1.47 through 2.3.3, and `@bsv/wallet-toolbox-mobile` from its initial 1.3.21 release through 2.3.3, are affected. All three packages are patched in version 2.4.0. Applications unable to upgrade should avoid remote `StorageClient` providers, use local storage, or independently verify every transaction output’s locking script and value against the original request before signing

CWE CWE-1288
Vendor bsv-blockchain
Product @bsv/wallet-toolbox
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for bsv-blockchain @bsv/wallet-toolbox

Be the first to know when new unknown vulnerabilities affecting bsv-blockchain @bsv/wallet-toolbox are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

bsv-blockchain / @bsv/wallet-toolbox
>= 1.1.47, < 2.4.0
bsv-blockchain / @bsv/wallet-toolbox-client
>= 1.1.47, < 2.4.0
bsv-blockchain / @bsv/wallet-toolbox-mobile
>= 1.3.21, < 2.4.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/bsv-blockchain/ts-stack/security/advisories/GHSA-36f9-7rg5-cpf8 github.com: https://github.com/bsv-blockchain/ts-stack/commit/3a11f6111919245a3090e9f3895cfc4f21a80d28 github.com: https://github.com/bsv-blockchain/ts-stack/commit/5492cabbef4ddc7f60cc49cdf5d8c74ed2e5d949 github.com: https://github.com/bsv-blockchain/ts-stack/commit/5ee60395e78e8b822d9a78efeacc6039c249819b github.com: https://github.com/bsv-blockchain/wallet-toolbox/commit/ca651b067c0238cd8b1ddd3af225daa503857a07