Intel

AIKIDO-2025-10174

cosmwasm-std is vulnerable to Authentication Bypass

Authentication BypassCVE-2025-25500 Published Mar 21, 2025

53

Medium Risk

This Affects:

RUSTcosmwasm-std
1.0.0 - 2.1.3
Fixed in 2.2.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Missing Authentication for a Critical Function due to inadequate runtime capability validation. This allows an attacker to execute unauthorized actions on the blockchain by deploying a contract without proper capability enforcement, potentially leading to unauthorized modifications or security breaches.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

cosmwasm-std is vulnerable to Authentication Bypass in versions 1.0.0 - 2.1.3.

How to fix this

Upgrade the cosmwasm-std library to the patch version.