Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: low
Invalid

Malicious mapping to solmate-bad inside foundry.toml

Summary

Inside the remappings section of foundry.toml, we see that:

remappings = [
'@openzeppelin/contracts=lib/openzeppelin-contracts/contracts',
'@solmate=lib/solmate-bad', <----------------------
]

Vulnerability Details

While in the current implementation, solmate libraries are not being used, anyone attempting to integrate it later might inadvertently be pointing to a malicious/bad implementation of solmate and cause unforeseen vulnerabilities. The 'bad' solmate can even be used to steal user funds.

Impact

Marking this as low because no immediate impact as per current implementation, but issues may arise in future.

Tools Used

Manual inspection.

Recommendations

Remove the mappings for any unused libraries.

Updates

Lead Judging Commences

0xnevi Lead Judge
over 1 year ago
0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.