TROYANOSYVIRUS
Back to CVEs

CVE-2026-31839

HIGH
8.2

Description

Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's digital confirmation workflow prior to v3.0.0. Hash-only validation trusted manifest hash fields that could be modified together with package content, allowing tampered confirmation packages to pass integrity checks. This vulnerability is fixed in 3.0.0.

CVE Details

CVSS v3.1 Score8.2
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
Published3/11/2026
Last Modified3/20/2026
Sourcenvd
Honeypot Sightings0

Affected Products

striae:striae

Weaknesses (CWE)

CWE-354

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.