delegatecall-vulnerability

1 article
sort: new top best
clear filter
0 7/10
vulnerability

A delegatecall vulnerability in oasisDEX's BuyCommand and SellCommand contracts allows attackers to execute arbitrary code by directly calling the external execute() function with the continuous flag set, bypassing the intended AutomationBot access control and potentially gaining unauthorized access to user CDP funds or causing system freeze via selfdestruct().

oasisDEX MakerDAO Immunefi DSProxy MultiplyProxyActions AutomationBot AutomationExecutor BuyCommand SellCommand BaseMPACommand DeFiSaver
trust-security.xyz · Trust · 20 hours ago · details