CVE-2025-25500
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 18, 2025
Updated: Mar 21, 2025
CWE ID 284
Summary
CVE-2025-25500 is a vulnerability affecting CosmWasm prior to version 2.2.0. This issue enables attackers to bypass capability restrictions in blockchains, exploiting a missing validation mechanism for runtime capabilities. As a result, attackers can deploy contracts without proper capability enforcement and execute unauthorized actions on the affected blockchain. This vulnerability poses a significant risk to the security and integrity of decentralized applications using CosmWasm.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.