VDB
Sign up
MEDIUM

GHSA-wfm2-rq5g-f8v5

@account-kit/smart-contracts Allowlist Module Bypass Vulnerability

Quick fix

GHSA-wfm2-rq5g-f8v5 — @account-kit/smart-contracts: upgrade to the fixed version with the command below.

npm install @account-kit/smart-contracts@4.28.2

Details

### Summary Allowlist module contains a bypass vulnerability

### Details The logic for using an allowlist on a Modular Account V2 contained a bug that allowed session keys to bypass any allowlist configuration

### Action If you are using @aa-sdk and/or @account-kit/smart-contracts between the versions of >=4.8.0 and <4.28.1, please upgrade to 4.28.2

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@account-kit/smart-contracts
Introduced in: 4.8.0Fixed in: 4.28.2
Fixnpm install @account-kit/smart-contracts@4.28.2

References