Vulnerability in OpenPGP.js library allowing message verification to be bypassed

A vulnerability has been identified in the OpenPGP.js library (CVE-2025-47934) that allows an attacker to send a modified message, which will be perceived by the recipient as verified (the functions openpgp.verify and openpgp.decrypt will return a successful digital signature verification indicator, despite the content being replaced and differing from the data for which the signature was created). The vulnerability has been fixed in OpenPGP.js releases 5.11.3 and 6.1.1. The issue only affects the OpenPGP.js 5.x and 6.x branches and does not impact OpenPGP.js 4.x.

The OpenPGP.js library provides a self-contained implementation of the OpenPGP protocol in JavaScript, allowing for encryption operations in the browser and working with digital signatures based on public keys. The project is developed by Proton Mail and, in addition to facilitating end-to-end message encryption in Proton Mail, is used in projects such as FlowCrypt, Mymail-Crypt, UDC, Encrypt.to, PGP Anywhere, and Passbolt.

The vulnerability affects the verification procedures embedded in the signature text (openpgp.verify) and signed and encrypted messages (openpgp.decrypt). An attacker can use existing signed messages to create new messages, in which unpacking with the vulnerable version of OpenPGP.js will extract the substituted content, differing from the content of the original signed message. The vulnerability does not affect signatures distributed separately from the text (the issue only occurs when the signature is transmitted together with the text as a single block of data).

To create a spoofed message, the attacker only needs one message with an embedded or separate signature, along with knowledge of the original data that was signed in that message. The attacker can modify the message so that the altered version's signature will still be considered valid. Similarly, encrypted messages with signatures can be altered, where unpacking them will return data added by the attacker.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster