GHSA-4jmp-x7mh-rgmr

Suggest an improvement
Source
https://github.com/advisories/GHSA-4jmp-x7mh-rgmr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-4jmp-x7mh-rgmr/GHSA-4jmp-x7mh-rgmr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4jmp-x7mh-rgmr
Aliases
Published
2025-12-12T20:15:03Z
Modified
2026-02-03T03:11:20Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Finality Provider vulnerable to anti-slashing bypassing due to misconfiguration
Details

Summary

The anti-slashing is not effective if the attacker can access EOTS manager endpoints.

Impact

If the EOTS manager endpoints are open to public without HMAC protection, the attacker can manually cause slashing of the finality provider through the RPC endpoints.

Report credits go to: x.com/RebelsRunways

Database specific
{
    "cwe_ids":  [
        "CWE-285"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-12-12T20:15:03Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Go
github.com/babylonlabs-io/finality-provider

Package

Name
github.com/babylonlabs-io/finality-provider
View open source insights on deps.dev
Purl
pkg:golang/github.com/babylonlabs-io/finality-provider

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.4

Database specific

last_known_affected_version_range
"<= 1.0.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-4jmp-x7mh-rgmr/GHSA-4jmp-x7mh-rgmr.json"
github.com/babylonlabs-io/finality-provider

Package

Name
github.com/babylonlabs-io/finality-provider
View open source insights on deps.dev
Purl
pkg:golang/github.com/babylonlabs-io/finality-provider

Affected ranges

Affected versions

1.*
1.1.0-rc.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-4jmp-x7mh-rgmr/GHSA-4jmp-x7mh-rgmr.json"
github.com/babylonlabs-io/finality-provider

Package

Name
github.com/babylonlabs-io/finality-provider
View open source insights on deps.dev
Purl
pkg:golang/github.com/babylonlabs-io/finality-provider

Affected ranges

Affected versions

1.*
1.1.0-rc.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-4jmp-x7mh-rgmr/GHSA-4jmp-x7mh-rgmr.json"
github.com/babylonlabs-io/finality-provider

Package

Name
github.com/babylonlabs-io/finality-provider
View open source insights on deps.dev
Purl
pkg:golang/github.com/babylonlabs-io/finality-provider

Affected ranges

Affected versions

1.*
1.99.0-devnet.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-4jmp-x7mh-rgmr/GHSA-4jmp-x7mh-rgmr.json"