PT-2026-24744 · Npm+3 · @Striae-Org/Striae+1
Stephen Jlu
·
Published
2026-03-11
·
Updated
2026-03-12
·
CVE-2026-31839
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Striae versions prior to 3.0.0
Description
Striae is a firearms examiner's comparison companion. A high-severity integrity bypass issue existed in the digital confirmation workflow. The validation process relied on hash values from the package manifest, which could be altered alongside the package content. This allowed manipulated confirmation packages to pass integrity checks. The issue affects users who depend on digital confirmations for immutability and chain-of-custody control. An attacker with access to an exported package could modify confirmation data and recalculate hashes, bypassing hash-only checks.
Recommendations
Upgrade to version 3.0.0 or later.
Treat hash-only validation as a tamper indicator, not proof of immutability.
Restrict package exchange to trusted authenticated internal channels.
Require out-of-band reviewer attestation for sensitive confirmation workflows.
Pause imports from untrusted sources until upgraded.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Striae-Org/Striae
Striae