Allowlist module contains a bypass vulnerability
The logic for using an allowlist on a Modular Account V2 contained a bug that allowed session keys to bypass any allowlist configuration
If you are using @aa-sdk and/or @account-kit/smart-contracts between the versions of >=4.8.0 and <4.28.1, please upgrade to 4.28.2
{ "nvd_published_at": null, "cwe_ids": [ "CWE-288" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-04-29T15:11:41Z" }