@account-kit/smart-contracts Allowlist Module Bypass Vulnerability
Package
Affected versions
>= 4.8.0, < 4.28.2
Patched versions
4.28.2
Description
Published to the GitHub Advisory Database
Apr 29, 2025
Reviewed
Apr 29, 2025
Summary
Allowlist module contains a bypass vulnerability
Details
The logic for using an allowlist on a Modular Account V2 contained a bug that allowed session keys to bypass any allowlist configuration
Action
If you are using @AA-SDK and/or @account-kit/smart-contracts between the versions of >=4.8.0 and <4.28.1, please upgrade to 4.28.2
References