highLogic errorEVM-Solidity
Collective: `VerbsToken.tokenURI()` is vulnerable to JSON injection attacks
- Payout
- $0
- Protocol
- Collective
- Disclosed
- Feb 8, 2024
- Source
- code4rena
The Collective protocol is vulnerable to JSON injection because it fails to sanitize user-provided metadata when creating new art pieces. By injecting special characters into the image or animation URL fields, an attacker can manipulate the metadata returned b …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2023-12-revolutionprotocol-findings/issues/167
- https://github.com/code-423n4/2023-12-revolutionprotocol-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.