PT-2025-11600 · Cosmwasm · Cosmwasm

Published

2025-03-18

·

Updated

2025-03-18

·

CVE-2025-25500

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions CosmWasm versions prior to 2.2.0
Description The issue allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This enables attackers to deploy a contract without capability enforcement and execute unauthorized actions on the blockchain.
Recommendations For versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue. As a temporary workaround, consider restricting contract deployment to trusted sources until the update is applied.

Exploit

Fix

Improper Access Control

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-25500
GHSA-CG8R-JWG7-R2X4

Affected Products

Cosmwasm