CVE-2025-46834
Last modified
CVE-2025-46834 is a medium-severity vulnerability rated 6.6/10 on the CVSS scale. Alchemy's Modular Account is a smart contract account that is compatible with ERC-4337 and ERC-6900. In versions on the 2.x branch prior to commit 5e6f540d249afcaeaf76ab95517d0359fde883b0, owners of Modular Accounts can grant session keys (scoped external keys) to external parties and would use the allowlist module to restrict which external contracts can be accessed by the session key. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Alchemy's Modular Account is a smart contract account that is compatible with ERC-4337 and ERC-6900. In versions on the 2.x branch prior to commit 5e6f540d249afcaeaf76ab95517d0359fde883b0, owners of Modular Accounts can grant session keys (scoped external keys) to external parties and would use the allowlist module to restrict which external contracts can be accessed by the session key. There is a bug in the allowlist module in that we don't check for the `executeUserOp` -> `execute` or `executeBatch` path, effectively allowing any session key to bypass any access control restrictions set on the session key. Session keys are able to access ERC20 and ERC721 token contracts amongst others, transferring all tokens from the account out andonfigure the permissions on external modules on session keys. They would be able to remove all restrictions set on themselves this way, or rotate the keys of other keys with higher privileges into keys that they control. Commit 5e6f540d249afcaeaf76ab95517d0359fde883b0 fixes this issue.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-46834?
How severe is CVE-2025-46834?
How do I fix CVE-2025-46834?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-46825Kanboard is project management software that focuses on the …5.4
- CVE-2025-46826insa-auth is an authentication server for INSA Rouen. A mino…1.3
- CVE-2025-46827Graylog is a free and open log management platform. Prior to…5.4
- CVE-2025-46828WeGIA is a web manager for charitable institutions. An unau…9.8
- CVE-2025-4683The MStore API – Create Native Android & iOS Apps On The Clo…4.3
- CVE-2025-46833Programs/P73_SimplePythonEncryption.py illustrates a simple …4.6
- CVE-2025-46835Git GUI allows you to use the Git source control management …8.5
- CVE-2025-46836net-tools is a collection of programs that form the base set…6.6
- CVE-2025-46837Adobe Experience Manager versions 6.5.22 and earlier are aff…8.7
- CVE-2025-46838Adobe Experience Manager versions 6.5.22 and earlier are aff…5.4
- CVE-2025-4684The BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magaz…6.4
- CVE-2025-46840Adobe Experience Manager versions 6.5.22 and earlier are aff…8.7
Are you affected by CVE-2025-46834?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
