Skip to content

Critical: Authorization flaw in TellerV2 potentially enabling unauthorized fund transfers… private disclosure #254

@cyberdaveonline

Description

@cyberdaveonline

Hi, I’m an independent security researcher. I’ve identified a high-impact vulnerability in TellerV2 related to forwarder authorization that can lead to unauthorized lender fund transfers under certain conditions.

I’ve developed a working PoC on a forked environment and would like to disclose this responsibly.

Could you please point me to the appropriate security contact or confirm if I can share the full report here under a private disclosure?

Happy to coordinate on a fix and disclosure timeline. Also open to discussing a bug bounty/reward for the finding.

Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions