The harvest function allows processing amounts larger than the configured maximumExpectedValue, potentially bypassing an important safety limit.
In IAlchemist.sol, maximumExpectedValue is defined as a safety parameter but can be bypassed:
PoC:
Safety limits can be bypassed
Potential for larger than intended harvests
Risk of economic damage due to uncapped operations
Foundry
Manual Review
1. Add value check in harvest function:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.