uninitialized-data

1 article
Sort: New Top Best
clear filter
0
vulnerability

Morpho Finance's PositionsManager implementation contract can be directly called (bypassing proxy) with arbitrary state mutation via unvalidated delegatecall, potentially allowing attackers to trigger selfdestruct and shut down the system. The vulnerability stems from uninitialized storage pointers and lack of access controls on dangerous delegatecall operations.

Morpho Finance PositionsManager MorphoStorage interestRatesManager
trust-security.xyz · Trust · 4 hours ago · details