mediumFront-running / MEVEVM-Solidity
Palmera: Malicious users can front-run host users safe management actions and add those safes as root for wrong org
- Payout
- $0
- Protocol
- Palmera
- Disclosed
- Jun 25, 2024
- Source
- hats
Palmera's root-safe creation flow lets any root-safe caller assign an arbitrary Safe address as the root of their organization without verifying that the target Safe consented or belongs to them. Because a Safe can only be registered to one organization, an at …
Similar reports
- No close matches yet.
References
- https://github.com/hats-finance/Palmera-0x5fee7541ddcd51ba9f4af606f87b2c42eea655be/issues/50
- https://github.com/hats-finance/Palmera-0x5fee7541ddcd51ba9f4af606f87b2c42eea655be
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.