GHSA-29h2-jr22-frmh: OpenZeppelin Confidential Contracts `VestingWalletConfidential`: a malicious ERC-7984 token is able to extract
VULNsource · GTH
HIGHHigh-risk vulnerability
### Impact Two locations consume an encrypted handle returned by an untrusted external party and use it without verifying that the party is ACL-authorized on it. #### `VestingWalletConfidential` Malicious users can call `release` with a malicious token. This token could return an alternative handle on `confidentialBalanceOf`, which represents the balance of the vesting wallet on an alternative ERC-7984 token (or any other handle that the vesting wallet has access to). …
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected