XRP Ledger discloses a vulnerability in the new version of the XRPL JavaScript library and recommends that projects upgrade to the fixed version as soon as possible

PA一线
PA一线04/23/2025, 12:09 AM

PANews reported on April 23 that according to The Block, the XRP Ledger Foundation warned that the recently released new version of the XRPL JavaScript library used to build applications may have potential vulnerabilities and urged projects to update to patched versions of the code. The problem was discovered by Charlie Eriksen, a malware researcher at Aikido Security, who said this "backdoor" could lead to a "potentially catastrophic" supply chain attack. The affected versions are v4.2.1 to v4.2.4 and v2.14.2, limited to code hosted on NPM. The foundation has released a fixed version v4.2.5 and recommends that related projects upgrade as soon as possible. The vulnerability does not affect the XRP Ledger itself or its GitHub code base.

Share to:

Author: PA一线

This content is provided for informational purposes only and does not constitute investment advice.

Follow PANews official accounts, let's navigate bull and bear markets together