{"id":"CVE-2024-41945","aliases":["GHSA-3jcg-vx7f-j6qf"],"url":"https://o3.security/vulnerability/CVE-2024-41945","summary":"The fuels-ts typescript SDK has no awareness of to-be-spent transactions","details":"fuels-ts is a library for interacting with Fuel v2.  The typescript SDK has no awareness of to-be-spent transactions causing some transactions to fail or silently get pruned as they are funded with already used UTXOs. The problem occurs, because the `fund` function in `fuels-ts/packages/account/src/account.ts` gets the needed ressources statelessly with the function `getResourcesToSpend` without taking into consideration already used UTXOs. This issue will lead to unexpected SDK behaviour, such as a transaction not getting included in the `txpool` / in a block or a previous transaction silently getting removed from the `txpool` and replaced with a new one.","published":"2024-07-30T19:42:06.663Z","modified":"2026-07-15T01:49:10.417462358Z","cvss":{"score":3.1,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@fuel-ts/account","fixedVersion":"0.93.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41945.json"},{"type":"ADVISORY","url":"https://github.com/FuelLabs/fuels-ts/security/advisories/GHSA-3jcg-vx7f-j6qf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-41945"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:10.417462358Z"}}