CVE-2023-33252: 0kims Snarkjs
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.
Affected products
- 0kims Snarkjs: up to and including 0.6.11
Published 2023-05-21. Last modified 2026-06-17.