{"id":"GHSA-8pfh-j44r-f654","aliases":["GO-2025-4041"],"url":"https://o3.security/vulnerability/GHSA-8pfh-j44r-f654","summary":"Cosmos EVM Vulnerability","details":"## Patches\nPatched in versions `v0.3.1`, `v0.4.2`, and in the `v0.5.0` release. More information will be disclosed at a later point to ensure chains have time to safely upgrade.\n\n## Workarounds\nNo workarounds for chains that make use of static or dynamic precompiles. Upgrading is strongly recommended.\n\n## Testing\nTests are introduced in every affected version.\n\n## Credits\nSpecial thanks to @yihuang for the help on this issue.","published":"2025-10-21T18:04:34Z","modified":"2025-11-05T19:57:44.486700Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/cosmos/evm","fixedVersion":"0.3.2"},{"ecosystem":"Go","name":"github.com/cosmos/evm","fixedVersion":"0.4.2"}],"fix":{"url":"https://github.com/cosmos/evm/commit/79089feebe79ce1f35250ba457cbd436e6bfff8b","label":"cosmos/evm@79089fe"},"references":[{"type":"WEB","url":"https://github.com/cosmos/evm/security/advisories/GHSA-8pfh-j44r-f654"},{"type":"WEB","url":"https://github.com/cosmos/evm/commit/79089feebe79ce1f35250ba457cbd436e6bfff8b"},{"type":"PACKAGE","url":"https://github.com/cosmos/evm"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-11-05T19:57:44.486700Z"}}