GHSA-8pf3-6fgr-3g3g
Dashboard / Vulnerabilities / GHSA-8pf3-6fgr-3g3g
Summary: `chainId` may be outdated if user changes chains as part of connection in @web3-react
Details: ### Impact `chainId` may be outdated if the user changes chains as part of the connection flow. This means that the value of `chainId` returned by `useWeb3React()` may be incorrect. In an application, this means that any data derived from `chainId` could be incorrect. For example, if a swapping application derives a wrapped token contract address from the `chainId` *and* a user has changed chains as part of their connection flow the application could cause the user to send funds to the incorrect address when wrapping. This is a common approach when using other foundational libraries like [`ethers`](https://github.com/ethers-io/ethers.js), and most users of v8 will want to upgrade past the affected versions. ### Patches Patched in https://github.com/Uniswap/web3-react/pull/749. Users of [email protected] should upgrade to at least: - @web3-react/coinbase-wallet@^8.0.35-beta.0 - @web3-react/eip1193@^8.0.27-beta.0 - @web3-react/metamask@^8.0.30-beta.0 - @web3-react/walletconnect@^8.0.37-beta.0 ### Workarounds N/A ### References N/A
References: https://github.com/Uniswap/web3-react/security/advisories/GHSA-8pf3-6fgr-3g3g, https://nvd.nist.gov/vuln/detail/CVE-2023-30543, https://github.com/Uniswap/web3-react/pull/749, https://github.com/Uniswap/web3-react
Affected packages
Package
Name: @web3-react/coinbase-wallet
Purl: pkg:npm/%40web3-react/coinbase-wallet
Affected ranges
Type: SEMVER
Events:
