CVE Explorer
CVE-2026-48815
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"sigstore-js","vendor":"sigstore","versions":[{"status":"affected","version":"< 4.1.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:efdd75329dc8059917f88e421215b691a121017751e970656eaeadddc643337c · sha256:537cdf31e0f295ec… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:efdd75329dc8059917f88e421215b691a121017751e970656eaeadddc643337c · sha256:537cdf31e0f295ec… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-347","description":"CWE-347: Improper Verification of Cryptographic Signature","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:efdd75329dc8059917f88e421215b691a121017751e970656eaeadddc643337c · sha256:537cdf31e0f295ec… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/sigstore/sigstore-js/commit/7845532f9d17f6f765363dbee82b01bd159fb52b","tags":["x_refsource_MISC"],"url":"https://github.com/sigstore/sigstore-js/commit/7845532f9d17f6f765363dbee82b01bd159fb52b"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:efdd75329dc8059917f88e421215b691a121017751e970656eaeadddc643337c · sha256:537cdf31e0f295ec… · /containers/cna/references/2
{"name":"https://github.com/sigstore/sigstore-js/pull/1658","tags":["x_refsource_MISC"],"url":"https://github.com/sigstore/sigstore-js/pull/1658"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:efdd75329dc8059917f88e421215b691a121017751e970656eaeadddc643337c · sha256:537cdf31e0f295ec… · /containers/cna/references/1
{"name":"https://github.com/sigstore/sigstore-js/releases/tag/sigstore%404.1.1","tags":["x_refsource_MISC"],"url":"https://github.com/sigstore/sigstore-js/releases/tag/sigstore%404.1.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:efdd75329dc8059917f88e421215b691a121017751e970656eaeadddc643337c · sha256:537cdf31e0f295ec… · /containers/cna/references/3
{"name":"https://github.com/sigstore/sigstore-js/security/advisories/GHSA-52v5-jr5w-gjxr","tags":["x_refsource_CONFIRM"],"url":"https://github.com/sigstore/sigstore-js/security/advisories/GHSA-52v5-jr5w-gjxr"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:efdd75329dc8059917f88e421215b691a121017751e970656eaeadddc643337c · sha256:537cdf31e0f295ec… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/sigstore/sigstore-js/security/advisories/GHSA-52v5-jr5w-gjxr"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:efdd75329dc8059917f88e421215b691a121017751e970656eaeadddc643337c · sha256:537cdf31e0f295ec… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.