MEDIUM
GHSA-wfm2-rq5g-f8v5
@account-kit/smart-contracts Allowlist Module Bypass Vulnerability
Quick fix
GHSA-wfm2-rq5g-f8v5 — @account-kit/smart-contracts: upgrade to the fixed version with the command below.
npm install @account-kit/smart-contracts@4.28.2Details
### Summary Allowlist module contains a bypass vulnerability
### Details The logic for using an allowlist on a Modular Account V2 contained a bug that allowed session keys to bypass any allowlist configuration
### Action If you are using @aa-sdk and/or @account-kit/smart-contracts between the versions of >=4.8.0 and <4.28.1, please upgrade to 4.28.2
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@account-kit/smart-contracts
Introduced in:
4.8.0Fixed in: 4.28.2Fix
npm install @account-kit/smart-contracts@4.28.2