CVE-2026-56744
Published:September 24, 2026
Updated:October 09, 2026
"@bsv/wallet-toolbox" provides BRC-100 wallet signing and storage components, while "@bsv/wallet-toolbox-client" and "@bsv/wallet-toolbox-mobile" provide client-focused distributions for standard and mobile applications using wallet storage services. A vulnerability in these packages causes transactions created through a remote "StorageClient" to trust output locking scripts returned by the storage provider without verifying that they match the outputs requested by the caller. A malicious or compromised storage provider can substitute a recipient script or inject an additional output, causing the wallet to sign and broadcast a transaction that redirects funds while the application and user interface continue to display the intended recipient. Source and npm publication history indicate that stable versions "@bsv/wallet-toolbox" and "@bsv/wallet-toolbox-client" from 1.1.47 through 2.3.3, and "@bsv/wallet-toolbox-mobile" from its initial 1.3.21 release through 2.3.3, are affected. All three packages are patched in version 2.4.0. Applications unable to upgrade should avoid remote "StorageClient" providers, use local storage, or independently verify every transaction output’s locking script and value against the original request before signing
Affected Packages
@bsv/wallet-toolbox-mobile (NPM):
Affected version(s) >=1.3.21 <2.4.0Fix Suggestion:
Update to version 2.4.0@bsv/wallet-toolbox (NPM):
Affected version(s) >=1.1.47 <2.4.0Fix Suggestion:
Update to version 2.4.0@bsv/wallet-toolbox-client (NPM):
Affected version(s) >=1.1.47 <2.4.0Fix Suggestion:
Update to version 2.4.0Related Resources (8)
Do you need more information?
Contact UsCVSS v4
Base Score:
8.7
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
HIGH
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
7.5
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE
Weakness Type (CWE)
Improper Validation of Consistency within Input
EPSS
Base Score:
0.30