@crossmint/wallets-sdk is vulnerable to Missing Authentication for Critical Function
82
High Risk
Affected versions of this package improperly allowed the approve operation to proceed without first ensuring the signer was authenticated. An attacker with access to a wallet session, compromised client state, or a context where approval could be triggered before authentication may be able to invoke approval flows and authorize a pending transaction or signature without the intended identity check. It could result in unauthorized transaction approval or signature confirmation on behalf of the victim.
You are affected if you are using a version that falls within the vulnerable range.
@crossmint/wallets-sdk is vulnerable to Missing Authentication for Critical Function in versions 1.0.0 - 1.0.7.
Upgrade the @crossmint/wallets-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant