GoSeverity: HighStatus: Published
Verifier treats p7.Certificates[0] as the signer: a signature by any untrusted key is reported Valid + TrustedChain and attributed to a trusted third-party certificate
The verifier used the first certificate in the signature (p7.Certificates[0]) as the signer, so a signature made with any untrusted key could be reported as Valid with a trusted chain and attributed to a trusted third-party certificate. Fixed in v1.0.0-rc4 (PR #175).