PT-2025-19429 · Npm · @Account-Kit/Smart-Contracts

Published

2025-04-29

·

Updated

2025-04-29

CVSS v4.0

6.6

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U

Summary

Allowlist module contains a bypass vulnerability

Details

The logic for using an allowlist on a Modular Account V2 contained a bug that allowed session keys to bypass any allowlist configuration

Action

If you are using @aa-sdk and/or @account-kit/smart-contracts between the versions of >=4.8.0 and <4.28.1, please upgrade to 4.28.2

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

GHSA-WFM2-RQ5G-F8V5

Affected Products

@Account-Kit/Smart-Contracts