GMS-2020-547: Holder can generate proof of ownership for credentials it does not control in vp-toolkit
The verifyVerifiablePresentation() method check the cryptographic integrity of the Verifiable Presentation, but it does not check if the
credentialSubject.id` DID matches the signer of the VP proof.
References
Detect and mitigate GMS-2020-547 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →