mediumVulnerability

GHSA-vjf8-9fx6-mv6x

The instruction `sponge_absorb_mem` Triton VM fails to verify that hashed values come from the claimed memory location. Malicious provers can substitute arbitrary data instead of actual memory contents. Any application using instruction `sponge_absorb_mem` to hash memory data can be given a proof for a forged hash that doesn't correspond to the actual memory. This breaks the security of memory-based commitments. The flaw was corrected in commits `17c7ba0a` and `ef9d9e72` by including the appropriate constraints.

Properties

ghsa_id
GHSA-vjf8-9fx6-mv6x
severity
medium
summary
Triton VM Soundness Vulnerability due to Missing Constraint
cve_id
GHSA-vjf8-9fx6-mv6x
is_ghsa_only
true
ghsa_published
2026-08-18T20:22:21Z
source_url
https://github.com/advisories/GHSA-vjf8-9fx6-mv6x
ghsa_updated
2026-08-18T20:22:22Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Insufficient Verification of Data Authenticity

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]rust/triton-vm

AFFECTS (1)

[Software]rust/triton-vm

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-vjf8-9fx6-mv6x — Ninja Signal Threat Intelligence | Ninja Signal