An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows attackers to deploy a contract without capability enforcement, and execute unauthorized actions on the blockchain.
References
Configurations
History
No history.
Information
Published : 2025-03-18 14:15
Updated : 2025-05-22 19:52
NVD link : CVE-2025-25500
Mitre link : CVE-2025-25500
CVE.ORG link : CVE-2025-25500
JSON object : View
Products Affected
cosmwasm
- cosmwasm
CWE
CWE-284
Improper Access Control
