Intel

AIKIDO-2026-10614

@crossmint/wallets-sdk is vulnerable to Missing Authentication for Critical Function

Missing Authentication for Critical Function Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 28, 2026

82

High Risk

This Affects:

JS@crossmint/wallets-sdk
1.0.0 - 1.0.7
Fixed in 1.0.8
Are you affected? Scan for Free

TL;DR

Affected versions of this package improperly allowed the approve operation to proceed without first ensuring the signer was authenticated. An attacker with access to a wallet session, compromised client state, or a context where approval could be triggered before authentication may be able to invoke approval flows and authorize a pending transaction or signature without the intended identity check. It could result in unauthorized transaction approval or signature confirmation on behalf of the victim.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@crossmint/wallets-sdk is vulnerable to Missing Authentication for Critical Function in versions 1.0.0 - 1.0.7.

How to fix this

Upgrade the @crossmint/wallets-sdk library to the patch version.