@lifi/perps-sdk-provider-lighter is vulnerable to Incorrect Authorization
60
Medium Risk
The Lighter provider signs TRANSFER actions through the generic signStandardWasmAction path using only the stored Lighter API key. Because no end-user L1 wallet signature binds the destination account and the amount to the account owner, a TRANSFER step handed to the signer authorizes a payout to an arbitrary L1 destination with the API key alone. The signed transaction is broadcast to Lighter and settles the move without the account owner's consent. The patch adds a dedicated signTransfer flow that requires the user's wallet to countersign the transfer as L1Sig and makes sign() reject TRANSFER.
You are affected if you are using a version that falls within the vulnerable range and your application uses the Lighter provider to sign transfer actions.
@lifi/perps-sdk-provider-lighter is vulnerable to Incorrect Authorization in versions 1.0.0 - 12.1.1.
Upgrade the @lifi/perps-sdk-provider-lighter library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.