highAccess controlEVM-Solidity
Revert Lend: `V3Vault::transform` does not validate the `data` input and allows a depositor to exploit any position approved on the transformer
- Payout
- $0
- Protocol
- Revert Lend
- Disclosed
- May 22, 2024
- Source
- code4rena
A parameter validation flaw in Revert Lend's `V3Vault.transform()` allows any vault position owner to execute arbitrary actions on external positions delegated to Revert transformers. When calling `transform()`, `V3Vault` validates vault ownership for the `tok …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-03-revert-lend-findings/issues/214
- https://github.com/code-423n4/2024-03-revert-lend-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.