All reports
mediumOracle manipulationEVM-Solidity

Panoptic: `_validatePositionList()` does not check for duplicate tokenIds, allowing attackers to bypass solvency checks

Payout
$0
Protocol
Panoptic
Disclosed
Jun 24, 2024
Source
code4rena

The Panoptic protocol improperly validates arrays of token IDs passed to its position-related functions. By failing to enforce a maximum array length or detect duplicate entries, the protocol allows an attacker to manipulate the internal position identificatio …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.