What's wrong?
iden3/snarkjs#358 suggested a vulnerability of the groth16 verifier in the latest snarkjs (v0.6.11). A fix iden3/snarkjs#359 was proposed but has yet to be merged. The issue is not related to circom so it's safe to stay as is, as discussed with @curryrasul offline.
How to fix it?
Upgrade snarkjs to the latest version as long as the fix is released.
What's wrong?
iden3/snarkjs#358 suggested a vulnerability of the groth16 verifier in the latest snarkjs (v0.6.11). A fix iden3/snarkjs#359 was proposed but has yet to be merged. The issue is not related to circom so it's safe to stay as is, as discussed with @curryrasul offline.
How to fix it?
Upgrade snarkjs to the latest version as long as the fix is released.