CVE-2026-31839Disclosure(striae / striae)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's digital confirmation workflow prior to v3.0.0. Hash-only validation trusted manifest hash fields that could be modified together with package content, allowing tampered confirmation packages to pass integrity checks. This vulnerability is fixed in 3.0.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-354

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • striae

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-12)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
striae

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-11: 1Mentions · 2026-03-12: 2Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 203-1103-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-122
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31839 Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's digital confirmation workflow prior to v3.0.0… https://www.cve.org/CVERecord?id=CVE-2026-31839 ----- Traducción: CVE-2026-31839 Str… http://infoflow.cloud`

    Post summary

    The post announces a high‑severity integrity‑bypass vulnerability (CVE‑2026‑31839) in Striae’s digital confirmation workflow, citing the CVE record but providing no PoC, exploit, or patch details.

    0000036
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31839 Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's digital confirmation workflow prior to v3.0.0… https://www.cve.org/CVERecord?id=CVE-2026-31839

    Post summary

    The post reports a high‑severity integrity bypass flaw in Striae’s digital confirmation workflow that existed before version 3.0.0, without indicating patches, PoCs, or active exploitation.

    00000249
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-31839 - High Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's digital confirmation workflow prior to v3.0.0. Hash-only validation tr... https://www.thehackerwire.com/vulnerability/CVE-2026-31839/ https://t.co/koUYBxqVC5

    Post summary

    The tweet announces a high‑severity integrity bypass vulnerability (CVE-2026-31839) affecting Striae’s digital confirmation workflow before version 3.0.0, linking to a detailed article.

    0000029
    134 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstriaestriae-node.js-

Explore more