{"id":"GHSA-8pfh-j44r-f654","summary":"Cosmos EVM Vulnerability","details":"## Patches\nPatched in versions `v0.3.1`, `v0.4.2`, and in the `v0.5.0` release. More information will be disclosed at a later point to ensure chains have time to safely upgrade.\n\n## Workarounds\nNo workarounds for chains that make use of static or dynamic precompiles. Upgrading is strongly recommended.\n\n## Testing\nTests are introduced in every affected version.\n\n## Credits\nSpecial thanks to @yihuang for the help on this issue.","aliases":["GO-2025-4041"],"modified":"2025-11-05T19:57:44.486700Z","published":"2025-10-21T18:04:34Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2025-10-21T18:04:34Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/cosmos/evm/security/advisories/GHSA-8pfh-j44r-f654"},{"type":"WEB","url":"https://github.com/cosmos/evm/commit/79089feebe79ce1f35250ba457cbd436e6bfff8b"},{"type":"PACKAGE","url":"https://github.com/cosmos/evm"}],"affected":[{"package":{"name":"github.com/cosmos/evm","ecosystem":"Go","purl":"pkg:golang/github.com/cosmos/evm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.3.0"},{"fixed":"0.3.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-8pfh-j44r-f654/GHSA-8pfh-j44r-f654.json"}},{"package":{"name":"github.com/cosmos/evm","ecosystem":"Go","purl":"pkg:golang/github.com/cosmos/evm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.4.0"},{"fixed":"0.4.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-8pfh-j44r-f654/GHSA-8pfh-j44r-f654.json"}}],"schema_version":"1.9.0"}