Executive brief
vp-toolkit is a library for verifying digital credentials used in blockchain-based identity systems. The vulnerability allows an attacker to forge or modify credentials because the library's verification function fails to confirm that the credential's issuer matches the entity that digitally signed it. This could enable fraudulent credential issuance or impersonation in systems relying on this library.
Technical details
The verifyVerifiableCredential() method in vp-toolkit performs cryptographic integrity checks but does not validate that the credential.issuer DID (decentralized identifier) matches the actual signer identified in credential.proof.verificationMethod. This is a signature validation bypass allowing an attacker to create credentials that appear authentic but claim to be from any issuer. The vulnerability affects verifiers consuming credentials. The fix was released in version 0.2.2; the workaround is to independently verify the issuer's public key from the verification method field.
Affected products
- Rabobank vp-toolkit before 0.2.2
Timeline
- 2020-03-06: disclosed: Vulnerability publicly disclosed
- 2020-02-28: patched: Patch available in version 0.2.2