CRITICAL 9.1 npm

sm-crypto Affected by Private Key Recovery in SM2-PKE

GHSA-pgx9-497m-6c4v · CVE-2026-23966

Published · Modified

Description

Summary

A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto. By interacting with the SM2 decryption interface multiple times, an attacker can fully recover the private key within approximately several hundred interactions.

Credit

This vulnerability was discovered by:

  • XlabAI Team of Tencent Xuanwu Lab
  • Atuin Automated Vulnerability Discovery Engine

Ready to move

Start Securing

Free, no credit card | First findings in minutes