All reports
highAccess controlEVM-Solidity

reNFT: An attacker is able to hijack any ERC721 / ERC1155 he borrows because guard is missing validation on the address supplied to function call `setFallbackHandler()`

Payout
$0
Protocol
reNFT
Disclosed
Mar 20, 2024
Source
code4rena

reNFT rents out ERC721/ERC1155 assets that are held inside Gnosis Safes guarded by a whitelist that blocks dangerous function selectors. The guard, however, never validates the address argument supplied to the Safe's setFallbackHandler(address) function. A ren …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.