Skip to content

Allowlist Module Bypass Vulnerability

Moderate
ryanlabouve published GHSA-wfm2-rq5g-f8v5 Apr 28, 2025

Package

npm @account-kit/smart-contracts (npm)

Affected versions

>=4.8.0 <4.28.1

Patched versions

>=4.28.2

Description

Summary

Allowlist module contains a bypass vulnerability

Details

The logic for using an allowlist on a Modular Account V2 contained a bug that allowed session keys to bypass any allowlist configuration

Action

If you are using @AA-SDK and/or @account-kit/smart-contracts between the versions of >=4.8.0 and <4.28.1, please upgrade to 4.28.2

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs

Credits