code-423n4 / 2021-12-amun-findings

0 stars 0 forks source link

`callFacet` is based on unprotected calls #252

Closed code423n4 closed 2 years ago

code423n4 commented 2 years ago

Handle

0x0x0x

Vulnerability details

callFacet is based on unprotected calls and user funds can get stolen using them. This is unsafe for users and at least this risk has to be better documented.

loki-sama commented 2 years ago

so maybe need to be documented better. But that is the intended behavior.

0xleastwood commented 2 years ago

As external calls are only initiated by an account satisfying the protectedCall modifier, it doesn't seem like this would be an issue. As the sponsor has pointed out, this is intended behaviour by the contract.