All reports
highAccess controlEVM-Solidity

Revert Lend: `V3Vault::transform` does not validate the `data` input and allows a depositor to exploit any position approved on the transformer

Payout
$0
Protocol
Revert Lend
Disclosed
May 22, 2024
Source
code4rena

A parameter validation flaw in Revert Lend's `V3Vault.transform()` allows any vault position owner to execute arbitrary actions on external positions delegated to Revert transformers. When calling `transform()`, `V3Vault` validates vault ownership for the `tok …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.