Intel

AIKIDO-2025-10160

cosmossdk.io/x/group is vulnerable to Improper Handling of Exceptional Conditions

Improper Handling of Exceptional ConditionsGHSA-47ww-ff84-4jrg Published Mar 17, 2025

87

High Risk

This Affects:

GOcosmossdk.io/x/group
0.6.2 - 0.47.16
Fixed in 0.47.17
0.50.0 - 0.50.12
Fixed in 0.50.13
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper handling of exceptional conditions in the EndBlocker process. An attacker can exploit this by submitting malicious proposals that trigger errors, potentially causing the blockchain to halt and disrupting network operations.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

cosmossdk.io/x/group is vulnerable to Improper Handling of Exceptional Conditions in versions 0.6.2 - 0.47.16 and 0.50.0 - 0.50.12.

How to fix this

Upgrade the cosmossdk.io/x/group library to the patch version.