VDB
Sign up
HIGH8.7

GHSA-8f9f-pc5v-9r5h

Malicious takeover of previously owned ENS names

Quick fix

GHSA-8f9f-pc5v-9r5h — @ensdomains/ens: upgrade to the fixed version with the command below.

npm install @ensdomains/ens@0.4.0

Details

### Impact A user who owns an ENS domain can set a "trapdoor", allowing them to transfer ownership to another user, and later regain ownership without the new owner's consent or awareness.

### Patches

A new ENS deployment is being rolled out that fixes this vulnerability in the ENS registry. The registry is newly deployed at [0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e](https://etherscan.io/address/0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e).

### Workarounds Do not accept transfers of ENS domains from other users on the old registrar.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@ensdomains/ens
Introduced in: 0Fixed in: 0.4.0
Fixnpm install @ensdomains/ens@0.4.0

References