The currently set baseURI in RAACNFT represents test NFTs to not be used in production
The current baseURI is set to
Using an ipfs gateway, we can see it represents 7 identical NFTs with no attributes where the images are the same
https://ipfs.io/ipfs/QmZzEbTnUWs5JDzrLKQ9yGk1kvszdnwdMaVw9vNgjCFLo2/
This will cause the first minted NFTs to return bad data when using tokenURI
and display same pictures on NFT marketplace making the NFTs to not reflect their real value.
Impact is HIGH as it won't show the real NFT expected data but likelihood can be argued low as it can be solved by using the setBaseUri
function
baseURI should start with an empty string or be set to expected NFTs production data
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.