Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 PyPI

Vyper's `_abi_decode` input not validated in complex expressions

GHSA-cx2q-hfxr-rj97 · CVE-2023-42460 · PYSEC-2023-191

Published · Modified

Description

Impact

_abi_decode() does not validate input when it is nested in an expression. the following example gets correctly validated (bounds checked):

x: int128 = _abi_decode(slice(msg.data, 4, 32), int128)

however, the following example is not bounds checked

@external
def abi_decode(x: uint256) -> uint256:
    a: uint256 = convert(_abi_decode(slice(msg.data, 4, 32), (uint8)), uint256) + 1
    return a  # abi_decode(256) returns: 257

the issue can be triggered by constructing an example where the output of _abi_decode is not internally passed to make_setter (an internal codegen routine) or other input validating routine.

Patches

https://github.com/vyperlang/vyper/pull/3626

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

References

Are there any links users can visit to find out more?

Ready to move

Start Securing

Free, no credit card | First findings in minutes