{"id":"GHSA-wfm2-rq5g-f8v5","aliases":[],"url":"https://o3.security/vulnerability/GHSA-wfm2-rq5g-f8v5","summary":"@account-kit/smart-contracts Allowlist Module Bypass Vulnerability","details":"### Summary\nAllowlist module contains a bypass vulnerability\n\n### Details\nThe logic for using an allowlist on a Modular Account V2 contained a bug that allowed session keys to bypass any allowlist configuration\n\n### Action\nIf you are using @aa-sdk and/or @account-kit/smart-contracts between the versions of >=4.8.0 and <4.28.1, please upgrade to 4.28.2","published":"2025-04-29T15:11:41Z","modified":"2025-04-29T15:11:41Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@account-kit/smart-contracts","fixedVersion":"4.28.2"}],"fix":{"url":"https://github.com/alchemyplatform/aa-sdk/commit/b65bafdb9eec3a009df2cbabf09a35a76550e9d0","label":"alchemyplatform/aa-sdk@b65bafd"},"references":[{"type":"WEB","url":"https://github.com/alchemyplatform/aa-sdk/security/advisories/GHSA-wfm2-rq5g-f8v5"},{"type":"WEB","url":"https://github.com/alchemyplatform/aa-sdk/commit/b65bafdb9eec3a009df2cbabf09a35a76550e9d0"},{"type":"PACKAGE","url":"https://github.com/alchemyplatform/aa-sdk"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-04-29T15:11:41Z"}}