PT-2025-21362 · Unknown · Modular Account De Alchemy

Zer0Dot

·

Published

2025-05-15

·

Updated

2025-05-15

·

CVE-2025-46834

CVSS v4.0

6.6

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions: Modular Account de Alchemy versions prior to commit 5e6f540d249afcaeaf76ab95517d0359fde883b0
Description: The issue concerns a bug in the allowlist module of Modular Account de Alchemy, which is compatible with ERC-4337 and ERC-6900. This bug allows session keys to bypass access control restrictions, enabling them to access external contracts, including ERC20 and ERC721 token contracts. As a result, session keys can transfer all tokens from the account, configure permissions on external modules, remove restrictions, and rotate keys with higher privileges into keys they control.
Recommendations: For versions prior to commit 5e6f540d249afcaeaf76ab95517d0359fde883b0, update to a version that includes the fix provided in commit 5e6f540d249afcaeaf76ab95517d0359fde883b0 to resolve the issue. As a temporary workaround, consider restricting access to the executeUserOp path and its subsequent execute or executeBatch functions to prevent session keys from bypassing access control restrictions.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-46834
GHSA-JHP7-7CQ9-M4PV

Affected Products

Modular Account De Alchemy