Impact
The vulnerability allows an attacker to create a malicious PeerRecord that contains a victim’s peer ID but is signed with the attacker’s cryptographic key. Because the PeerStore verification logic only checks that the signature comes from the expected peer and does not confirm that the signed payload’s peerId matches the signer, the malicious record can be accepted and stored as if it were legitimate. The stored addresses can then be used for address‑book corruption, directed or redirected connections, and reachability disruption. While the base layer still verifies remote peer identity during connection upgrades, the poisoned addresses enable attackers to influence path selection and potentially deny service to the victim.
Affected Systems
This risk applies to environments that use libp2p/peer-store versions between 8.0.0 and 12.0.24 inclusive, specifically the @libp2p/peer-store component of the libp2p JavaScript networking stack.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity flaw. No EPSS score is reported, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves the gossipsub Peer Exchange path, where an attacker can impersonate a peer ID during peer discovery. Exploitation requires the attacker to be able to inject a custom PeerRecord into the network, which may be feasible for anyone with network access to the peer discovery mechanisms.
OpenCVE Enrichment
Github GHSA