arbitrary-contract-call

2 articles
sort: new top best
clear filter
0 7/10
vulnerability

Beanstalk's convertFacet function failed to validate the Well address parameter, allowing attackers to supply a malicious contract that could return arbitrary BEAN amounts and set conversion costs to zero, enabling theft of protocol funds without proper token withdrawal. The fix added validation to ensure the Well address is whitelisted and that the fromAmount is always non-zero.

Beanstalk Immunefi BEAN convertFacet Silo Well
medium.com · unknown · 17 hours ago · details
0 8/10
vulnerability

BendDAO's Sewer Pass Flash Claim contract contained an input validation vulnerability where the `airdropTokenAddresses` parameter was not validated against a whitelist, allowing NFT owners to deploy malicious token contracts that could withdraw staked ApeCoin during the flash loan execution without proper unstaking.

BendDAO Sewer Pass BAYC MAYC ApeCoin Ape Staking UserFlashclaimRegistryV3 AirdropFlashLoanReceiverV3 CVE-ID-16841
medium.com · unknown · 17 hours ago · details