Description
When a Solana Pay transaction is located using a reference key, it may be checked to represent a transfer of the desired amount to the recipient, using the supplied validateTransfer function. An edge case regarding this mechanism could cause the validation logic to validate multiple transfers.
Recommendation
Update the @solana/pay package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.2.0
- Patched version(s): 0.2.1
References
Could your website be exposed too?
SmartScanner can check your website for Solana Pay Vulnerable to Weakness in Transfer Validation Logic and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Validation bypass in frourio - CVE-2022-23623
- Editor.js vulnerable to Code Injection - CVE-2022-23474
- ejs is vulnerable to remote code execution due to weak input validation - CVE-2017-1000228
- matrix-appservice-irc vulnerable to IRC mode parameter confusion - CVE-2022-39202


