Intel

AIKIDO-2025-10344

@metamask/assets-controllers is vulnerable to Client-Side Injection Attacks

Client-Side Injection Attacks Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 3, 2025

20

Low Risk

This Affects:

JS@metamask/assets-controllers
33.0.0 - 65.0.0
Fixed in 66.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to phishing and malicious NFT metadata exploits due to insufficient URL validation in the UI layer, allowing attackers to bypass frontend checks and inject harmful links into NFT metadata. An attacker could craft malicious NFTs with embedded unsafe URLs that execute scripts, redirect to phishing sites, or trigger unwanted actions when rendered.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@metamask/assets-controllers is vulnerable to Client-Side Injection Attacks in versions 33.0.0 - 65.0.0.

How to fix this

Upgrade the @metamask/assets-controllers library to the patch version.