-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/evmos/evmos/v18 | go | <= 18.0.1 | 19.0.0 |
The vulnerability stemmed from improper authorization checks in the fundVestingAccount function. The original implementation validated the contract caller's authorization but used the message-specified funder address for actual fund transfers. This mismatch allowed attackers to create vesting accounts with arbitrary funders without proper authorization. The patch added critical validation that restricts the funder to either the transaction origin (EOA) or the contract caller when invoked through a smart contract, addressing the improper authorization (CWE-863).
Ongoing coverage of React2Shell