Description
iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.
Remediation
References
https://github.com/iden3/snarkjs/commits/master/src/groth16_verify.js
https://github.com/iden3/snarkjs/tags
Related Vulnerabilities
CVE-2021-29445 Vulnerability in npm package jose-node-esm-runtime
CVE-2023-4316 Vulnerability in maven package org.webjars.npm:zod
CVE-2019-19771 Vulnerability in npm package bitcoin-osp
CVE-2022-37422 Vulnerability in maven package fish.payara.server.internal.web:web-core
CVE-2023-3691 Vulnerability in maven package org.webjars.bowergithub.diguoyihao:layui