The function _authorizeUpgrade
lacks the checks to verify that it is only called by the owner.
The _authorizeUpgrade
should be only called by the owner so that only the owner can upgrade the contract but it lacks any such checks .
Anyone can upgrade the contract.
VS code
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.