Safety vulnerability ID: 58660
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Vyper 0.3.8 includes a fix for CVE-2023-32059: Prior to version 0.3.8, internal calls with default arguments are compiled incorrectly. Depending on the number of arguments provided in the call, the defaults are added not right-to-left, but left-to-right. If the types are incompatible, typechecking is bypassed. The ability to pass kwargs to internal functions is an undocumented feature that is not well known about.
https://github.com/vyperlang/vyper/security/advisories/GHSA-ph9x-4vc9-m39g
Latest version: 0.4.0
Vyper: the Pythonic Programming Language for the EVM
Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, internal calls with default arguments are compiled incorrectly. Depending on the number of arguments provided in the call, the defaults are added not right-to-left, but left-to-right. If the types are incompatible, typechecking is bypassed. The ability to pass kwargs to internal functions is an undocumented feature that is not well known about. The issue is patched in version 0.3.8. See CVE-2023-32059.
MISC:https://github.com/vyperlang/vyper/commit/c3e68c302aa6e1429946473769dd1232145822ac: https://github.com/vyperlang/vyper/commit/c3e68c302aa6e1429946473769dd1232145822ac
MISC:https://github.com/vyperlang/vyper/security/advisories/GHSA-ph9x-4vc9-m39g: https://github.com/vyperlang/vyper/security/advisories/GHSA-ph9x-4vc9-m39g
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application