PT-2025-31154 · Polkadot · Polkadot Frontier
Published
2025-07-28
·
Updated
2025-07-28
·
CVE-2025-54429
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Polkadot Frontier versions prior to 0822030
Description
Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. The implementation of
CallableByContract incorrectly identified contract addresses running under CREATE or CREATE2 as externally owned accounts (EOA) instead of correctly identifying them as contract accounts. This issue affects users utilizing custom precompile implementations that rely on distinguishing between AddressType::EOA and AddressType::Contract. The vulnerability is not directly exploitable in the predefined precompiles within Frontier.Recommendations
Update Polkadot Frontier to version 0822030 or later.
Exploit
Fix
Incorrect Type Conversion or Cast
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Polkadot Frontier