Описание
@account-kit/smart-contracts Allowlist Module Bypass Vulnerability
Summary
Allowlist module contains a bypass vulnerability
Details
The logic for using an allowlist on a Modular Account V2 contained a bug that allowed session keys to bypass any allowlist configuration
Action
If you are using @aa-sdk and/or @account-kit/smart-contracts between the versions of >=4.8.0 and <4.28.1, please upgrade to 4.28.2
Пакеты
Наименование
@account-kit/smart-contracts
npm
Затронутые версииВерсия исправления
>= 4.8.0, < 4.28.2
4.28.2
6.6 Medium
CVSS4
Дефекты
CWE-288
6.6 Medium
CVSS4
Дефекты
CWE-288