tiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environment
High severity
GitHub Reviewed
Published
Jun 29, 2025
in
bitcoinjs/tiny-secp256k1
•
Updated Jul 1, 2025
Give feedback on Dependabot alerts