All reports
highLogic errorEVM-Solidity

Collective: `VerbsToken.tokenURI()` is vulnerable to JSON injection attacks

Payout
$0
Protocol
Collective
Disclosed
Feb 8, 2024
Source
code4rena

The Collective protocol is vulnerable to JSON injection because it fails to sanitize user-provided metadata when creating new art pieces. By injecting special characters into the image or animation URL fields, an attacker can manipulate the metadata returned b …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.