Allowlist module contains a bypass vulnerability
The logic for using an allowlist on a Modular Account V2 contained a bug that allowed session keys to bypass any allowlist configuration
If you are using @aa-sdk and/or @account-kit/smart-contracts between the versions of >=4.8.0 and <4.28.1, please upgrade to 4.28.2
{
"cwe_ids": [
"CWE-288"
],
"github_reviewed": true,
"github_reviewed_at": "2025-04-29T15:11:41Z",
"nvd_published_at": null,
"severity": "MODERATE"
}