CVE-2020-11071: Simpleledger Slpjs
High severity, CVSS 8.6. EPSS: 0.9% chance of exploitation in the next 30 days.
SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This is fixed in version 0.27.2.
Affected products
- Simpleledger Slpjs: before 0.27.2 (fixed in 0.27.2)
Published 2020-05-12. Last modified 2026-06-17.