{"id":"GHSA-wfm2-rq5g-f8v5","summary":"@account-kit/smart-contracts Allowlist Module Bypass Vulnerability","details":"### Summary\nAllowlist module contains a bypass vulnerability\n\n### Details\nThe logic for using an allowlist on a Modular Account V2 contained a bug that allowed session keys to bypass any allowlist configuration\n\n### Action\nIf you are using @aa-sdk and/or @account-kit/smart-contracts between the versions of \u003e=4.8.0 and \u003c4.28.1, please upgrade to 4.28.2","modified":"2025-04-29T15:11:41Z","published":"2025-04-29T15:11:41Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-04-29T15:11:41Z","nvd_published_at":null,"cwe_ids":["CWE-288"]},"references":[{"type":"WEB","url":"https://github.com/alchemyplatform/aa-sdk/security/advisories/GHSA-wfm2-rq5g-f8v5"},{"type":"WEB","url":"https://github.com/alchemyplatform/aa-sdk/commit/b65bafdb9eec3a009df2cbabf09a35a76550e9d0"},{"type":"PACKAGE","url":"https://github.com/alchemyplatform/aa-sdk"}],"affected":[{"package":{"name":"@account-kit/smart-contracts","ecosystem":"npm","purl":"pkg:npm/%40account-kit/smart-contracts"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.8.0"},{"fixed":"4.28.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-wfm2-rq5g-f8v5/GHSA-wfm2-rq5g-f8v5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U"}]}