{"id":"CVE-2020-15131","aliases":["GHSA-6jmr-jfh7-xg3h"],"url":"https://o3.security/vulnerability/CVE-2020-15131","summary":"False-positive validity for NFT1 genesis transactions","details":"In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group token type as is required by the NFT1 specification. This is fixed in version 1.2.2.","published":"2020-07-30T15:15:13.150Z","modified":"2026-07-09T00:37:45.406799Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"slp-validate","fixedVersion":"1.2.2"}],"fix":{"url":"https://github.com/simpleledger/slp-validate.js/commit/3963cf914afae69084059b82483da916d97af65c","label":"simpleledger/slp-validate.js@3963cf9"},"references":[{"type":"ADVISORY","url":"https://github.com/simpleledger/slp-validate.js/security/advisories/GHSA-6jmr-jfh7-xg3h"},{"type":"FIX","url":"https://github.com/simpleledger/slp-validate.js/commit/3963cf914afae69084059b82483da916d97af65c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:37:45.406799Z"}}