fuels@0.42.0 vulnerabilities

Fuel TS SDK

Direct Vulnerabilities

Known vulnerabilities in the fuels package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
Improper Input Validation

fuels is a Fuel TS SDK

Affected versions of this package are vulnerable to Improper Input Validation via the fund function in fuels-ts/packages/account/src/account.ts file, that gets the needed resources statelessly with the function getResourcesToSpend without taking into consideration already used UTXOs. This vulnerability will lead to unexpected SDK behaviourthat could cause a transaction to not get included in the txpool/in a block or for a previous transaction to silently get removed from the txpool and be replaced with a new one.

How to fix Improper Input Validation?

Upgrade fuels to version 0.93.0 or higher.

<0.93.0