Beginner FriendlyFoundryNFT
100 EXP
View results
Submission Details
Severity: medium
Valid

incorrect `LEGEND_SNEK_URI` leads to incorrect Token URI

Summary

The LEGEND_SNEK_URI constant is incorrect.

Vulnerability Details

The LEGEND_SNEK_URI constant points to an image stored on IPFS rather then a JSON representation of a snek like the other SNEK_URI constants.

Impact

This leads to the rarityToTokenUri mapping being incorrectly set for legendary sneks. Which further leads to all legendary sneks having an incorrect tokenURI.

Tools Used

Manual Review
IPFS gateway

Recommendations

I recommend you change the LEGEND_SNEK_URI constant to the correct IPFS link.

It's worth noting that, whilst not in scope, the legend-snek.json file inside the repo is also incorrect, it's name is "Jungle Snek", when presumably it should be "Legendary Snek". So take extra care to verify that the IPFS JSON file is correct before changing the constant.

Updates

Lead Judging Commences

inallhonesty Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

LEGEND_SNEK_URI is wrong

inallhonesty Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

LEGEND_SNEK_URI is wrong

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.