PT-2025-21362 · Unknown · Modular Account De Alchemy
Zer0Dot
·
Published
2025-05-15
·
Updated
2025-05-15
·
CVE-2025-46834
CVSS v4.0
6.6
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions:
Modular Account de Alchemy versions prior to commit 5e6f540d249afcaeaf76ab95517d0359fde883b0
Description:
The issue concerns a bug in the allowlist module of Modular Account de Alchemy, which is compatible with ERC-4337 and ERC-6900. This bug allows session keys to bypass access control restrictions, enabling them to access external contracts, including ERC20 and ERC721 token contracts. As a result, session keys can transfer all tokens from the account, configure permissions on external modules, remove restrictions, and rotate keys with higher privileges into keys they control.
Recommendations:
For versions prior to commit 5e6f540d249afcaeaf76ab95517d0359fde883b0, update to a version that includes the fix provided in commit 5e6f540d249afcaeaf76ab95517d0359fde883b0 to resolve the issue. As a temporary workaround, consider restricting access to the
executeUserOp path and its subsequent execute or executeBatch functions to prevent session keys from bypassing access control restrictions.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modular Account De Alchemy