Executive brief
sm-crypto is a JavaScript library implementing the SM2 public-key cryptosystem, commonly used in Chinese applications for data encryption and digital signatures. A vulnerability in its SM2 decryption logic allows attackers to recover the user's private key through repeated interactions with the decryption interface—approximately several hundred calls suffice to fully extract the key. This compromises the confidentiality and integrity of all data protected by the affected key.
Technical details
The vulnerability is a private key recovery flaw in the SM2 decryption implementation (CWE-345: Insufficient Verification of Data Authenticity). An attacker can exploit the decryption interface via network access without authentication or user interaction to perform a key recovery attack. By sending multiple crafted ciphertexts to the decryption function and analyzing the responses, an attacker can gradually recover the full private key within several hundred interactions. The attack is purely algorithmic and requires no special privileges. This vulnerability was patched in version 0.3.14.
Affected products
- JuneAndGreen sm-crypto <0.3.14
Timeline
- 2026-01-21: disclosed: Advisory published
- 2026-01-21: patched: Fixed in version 0.3.14