mediumLogic errorEVM-Solidity
Rigor Protocol: `Project.changeOrder()` would work unexpectedly for non SCConfirmed tasks.
- Payout
- $0
- Protocol
- Rigor Protocol
- Disclosed
- Aug 7, 2026
- Source
- code4rena
In Rigor Protocol's Project.sol, the changeOrder() function is meant to let the project builder or contractor update a task's cost or subcontractor. For tasks that do not yet have a confirmed subcontractor, the function unconditionally routes through checkSign …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2022-08-rigor-findings/issues/232
- https://github.com/code-423n4/2022-08-rigor-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.