Pool owner can front-run borrower to snap extra fees
Lender.sol allows pool owners to update [pool loan interest rate](Pool owner can front-run loans to snap extra fee) at will. A malicious pool owner can sandwich-attack a lucrative loan to snap extra fees.
Borrower is charged more than expected interest rate.
Manual review
Add a uint256 maximumInterestRate input parameter to function borrow and check that the pool interest rate is not more than this value.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.