Skip to content

Conversation

@developerfred
Copy link

@developerfred developerfred commented Oct 18, 2025

Currently, a user can approve a third-party user they control to manage their shares, thus bypassing the 30-day lock and receiving tokens early.

This is a critical vulnerability; in this pull request, I fix it.

POC

@RubenSousaDinis
Copy link
Member

Hi @developerfred!

Thanks for raising this issue with us!

We confirm there's indeed an issue with the current contract as is. We will be deploying a new version of the Vault soon and the issue will be fixed there.

@developerfred
Copy link
Author

Thank you @RubenSousaDinis, I really like the talent protocol, so we need to mitigate any and all vulnerabilities that may be found. Thanks again!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants