Junglewise Threat Intelligence

CVE-2025-47934: OpenPGP.js message signature verification spoofing

CVE-2025-47934 · Severity: medium · CVSS 4 · Published 2025-05-19

Executive brief

OpenPGP.js is a JavaScript library used to encrypt and verify digital signatures in web applications. A flaw in its signature verification allows an attacker with a valid signature and plaintext to forge messages that appear validly signed, potentially enabling unauthorized message modification and authentication bypass in applications relying on this library.

Technical details

The vulnerability is an authentication bypass (CWE-347) in OpenPGP.js's signature verification logic. When verifying inline-signed or signed-and-encrypted messages, the openpgp.verify and openpgp.decrypt functions can be tricked into returning valid signature verification results even when the returned data does not match the originally signed content. An attacker who possesses one valid signature and the plaintext that was legitimately signed can craft a malicious message containing arbitrary data that will pass verification as legitimate. Detached signature verifications are unaffected because no signed data is returned in those cases. The attack requires network access and no authentication, making it exploitable remotely. The issue affects OpenPGP.js versions 5.0.1 through 5.11.2 and 6.0.0-alpha.0 through 6.1.0, with patches available in versions 5.11.3 and 6.1.1.

Affected products

  • OpenPGP.js openpgp 5.0.1 to 5.11.2, 6.0.0-alpha.0 to 6.1.0

Timeline

  • 2025-05-19: disclosed: Vulnerability published in GHSA and CVE databases

References