Description
iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.
Remediation
References
https://github.com/iden3/snarkjs/commits/master/src/groth16_verify.js
https://github.com/iden3/snarkjs/tags
Related Vulnerabilities
CVE-2021-37712 Vulnerability in npm package tar
CVE-2022-31051 Vulnerability in npm package semantic-release
CVE-2023-50422 Vulnerability in maven package com.sap.cloud.security:java-security
CVE-2023-32262 Vulnerability in maven package org.jenkins-ci.plugins:dimensionsscm
CVE-2020-27838 Vulnerability in maven package org.keycloak:keycloak-client-registration-api