PT-2025-18927 · Openvm · Openvm

Published

2025-05-02

·

Updated

2025-05-05

·

CVE-2025-46723

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenVM version 1.0.0
Description The issue is related to an overflow vulnerability in the AUIPC instruction decomposition of the OpenVM framework. A typo in the code results in incorrect range checking of the highest limb of pc, leading to a situation where a malicious prover can manipulate the destination register to take a different value than intended. This is achieved by making the decomposition overflow the BabyBear field.
Recommendations For OpenVM version 1.0.0, update to version 1.1.0 to resolve the issue. As a temporary workaround, consider restricting the use of the AUIPC instruction in the affected version until the patch is applied.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-14814
CVE-2025-46723
GHSA-JF2R-X3J4-23M7

Affected Products

Openvm