CVE-2020-22741: Baidu Xuperchain

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature.

Affected products

  • Baidu Xuperchain: version 3.6.0 only

Published 2021-07-19. Last modified 2026-06-17.