CVE-2025-58359 | ZcashFoundation frost up to 2.1.x refresh missing cryptographic step (GHSA-wgq8-vr6r-mqxm)
A vulnerability categorized as problematic has been discovered in ZcashFoundation frost up to 2.1.x. This issue affects the function frost_core::keys::refresh. The manipulation results in missing cryptographic step.
This vulnerability is reported as CVE-2025-58359. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.