PT-2025-11600 · Cosmwasm · Cosmwasm
Published
2025-03-18
·
Updated
2025-03-18
·
CVE-2025-25500
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CosmWasm versions prior to 2.2.0
Description
The issue allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This enables attackers to deploy a contract without capability enforcement and execute unauthorized actions on the blockchain.
Recommendations
For versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue. As a temporary workaround, consider restricting contract deployment to trusted sources until the update is applied.
Exploit
Fix
Improper Access Control
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cosmwasm