← voltar
CVE-2026-3194

Chia Blockchain RPC Server Master Passphrase get_private_key missing authentication

CVSS 2 LOWEPSS 0.2%CWE-287CWE-306
Vexday Risk Score
8Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 2EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
25 fev 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Master Passphrase Handler. This manipulation causes missing authentication. The attack can only be executed locally. The attack's complexity is rated as high. The exploitability is described as difficult. The exploit has been published and may be used. The vendor was informed early via email. A separate report via bugbounty was rejected with the reason "This is by design. The user is responsible for host security".
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
Chia · Blockchain

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →