lowVulnerability

GHSA-6hxq-p678-4hr2

## Summary `validateCertificatePath()` does not verify that an attestation's certificate chain actually terminates at a configured trust anchor. When walking the chain it stops at the first self-signed certificate it finds (which could be user-supplied), and exits early. This happens before the configured Apple/Google/etc trust anchor (which is concatenated to the end of the chain) is reached. A user can therefore register a credential and have the server accept it as if it were backed by a genuine Apple / Android SafetyNet / Yubikey / etc. ## Details `packages/server/src/helpers/validateCertificatePath.ts`: The configured trust anchor is appended to the end of the untrusted chain (line **83**): ```ts const x5cWithTrustAnchor = x5cCertsParsed.concat([anchor]); ``` The walk then verifies each cert was signed by the next, but breaks on the first self-signed cert (lines **104–116**): ```ts if (issuer.subject === issuer.issuer) { // Root cert detected, make sure it signed itself const issuerSignedIssuer = await issuer.verify( { publicKey: issuer.publicKey, signatureOnly: true }, WebCrypto, ); if (!issuerSignedIssuer) { throw new InvalidSubjectAndIssuer(); } break; // <-- exits before the appended trust anchor is ever checked if user supplied self-signed cert comes first } ``` The success condition is therefore "the certs form an internally-consistent chain ending in some self-signed cert" Rather than "the chain terminates at one of the configured trust anchors." ## Exploit shape ``` attacker sends: x5c = [ forgedLeaf (signed by attacker root), attackerSelfSignedRoot ] library builds: [ forgedLeaf, attackerSelfSignedRoot, <configured Apple/Google/etc root> ] walk: forgedLeaf -> attackerSelfSignedRoot (verifies, attacker controls both) attackerSelfSignedRoot is self-signed -> break attackerSelfSignedRoot -> configured root (NEVER CHECKED) ``` `return true`. The configured anc

Properties

ghsa_id
GHSA-6hxq-p678-4hr2
severity
low
summary
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
cve_id
GHSA-6hxq-p678-4hr2
is_ghsa_only
true
ghsa_published
2026-09-04T17:33:20Z
source_url
https://github.com/advisories/GHSA-6hxq-p678-4hr2
ghsa_updated
2026-09-04T17:33:24Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]npm/@simplewebauthn/server

AFFECTS (1)

[Software]npm/@simplewebauthn/server

HAS_WEAKNESS (2)

[Weakness]Improper Certificate Validation
[Weakness]Improper Following of a Certificate's Chain of Trust

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-6hxq-p678-4hr2 — Ninja Signal Threat Intelligence | Ninja Signal