VDB
Sign up
CRITICAL

GHSA-8pfh-j44r-f654

Cosmos EVM Vulnerability

Quick fix

GHSA-8pfh-j44r-f654 — github.com/cosmos/evm: upgrade to the fixed version with the command below.

go get github.com/cosmos/evm@v0.3.2

Details

## Patches Patched in versions `v0.3.1`, `v0.4.2`, and in the `v0.5.0` release. More information will be disclosed at a later point to ensure chains have time to safely upgrade.

## Workarounds No workarounds for chains that make use of static or dynamic precompiles. Upgrading is strongly recommended.

## Testing Tests are introduced in every affected version.

## Credits Special thanks to @yihuang for the help on this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/cosmos/evm
Introduced in: 0.3.0Fixed in: 0.3.2
Fixgo get github.com/cosmos/evm@v0.3.2
Go/github.com/cosmos/evm
Introduced in: 0.4.0Fixed in: 0.4.2
Fixgo get github.com/cosmos/evm@v0.4.2

References