GHSA-6hxq-p678-4hr2
## Summary `validateCertificatePath()` does not verify that an attestation's certificate chain actually terminates at a configured trust anchor. When walking the chain it stops at the first self-signed certificate it finds (which could be user-supplied), and exits early. This happens before the configured Apple/Google/etc trust anchor (which is concatenated to the end of the chain) is reached. A user can therefore register a credential and have the server accept it as if it were backed by a genuine Apple / Android SafetyNet / Yubikey / etc. ## Details `packages/server/src/helpers/validateCertificatePath.ts`: The configured trust anchor is appended to the end of the untrusted chain (line **83**): ```ts const x5cWithTrustAnchor = x5cCertsParsed.concat([anchor]); ``` The walk then verifies each cert was signed by the next, but breaks on the first self-signed cert (lines **104–116**): ```ts if (issuer.subject === issuer.issuer) { // Root cert detected, make sure it signed itself const issuerSignedIssuer = await issuer.verify( { publicKey: issuer.publicKey, signatureOnly: true }, WebCrypto, ); if (!issuerSignedIssuer) { throw new InvalidSubjectAndIssuer(); } break; // <-- exits before the appended trust anchor is ever checked if user supplied self-signed cert comes first } ``` The success condition is therefore "the certs form an internally-consistent chain ending in some self-signed cert" Rather than "the chain terminates at one of the configured trust anchors." ## Exploit shape ``` attacker sends: x5c = [ forgedLeaf (signed by attacker root), attackerSelfSignedRoot ] library builds: [ forgedLeaf, attackerSelfSignedRoot, <configured Apple/Google/etc root> ] walk: forgedLeaf -> attackerSelfSignedRoot (verifies, attacker controls both) attackerSelfSignedRoot is self-signed -> break attackerSelfSignedRoot -> configured root (NEVER CHECKED) ``` `return true`. The configured anc
Properties
- ghsa_id
- GHSA-6hxq-p678-4hr2
- severity
- low
- summary
- SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
- cve_id
- GHSA-6hxq-p678-4hr2
- is_ghsa_only
- true
- ghsa_published
- 2026-09-04T17:33:20Z
- source_url
- https://github.com/advisories/GHSA-6hxq-p678-4hr2
- ghsa_updated
- 2026-09-04T17:33:24Z
Related Entities (5)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph