CVE-2025-46834: Alchemy's Modular Account can use executeUserOp to bypass allowlist prevalidation hook

Published May 15, 2025
·
Updated

Alchemy's Modular Account is a smart contract account that is compatible with ERC-4337 and ERC-6900. In versions on the 2.x branch prior to commit 5e6f540d249afcaeaf76ab95517d0359fde883b0, owners of Modular Accounts can grant session keys (scoped external keys) to external parties and would use the allowlist module to restrict which external contracts can be accessed by the session key. There is a bug in the allowlist module in that we don't check for the executeUserOp -> execute or executeBatch path, effectively allowing any session key to bypass any access control restrictions set on the session key. Session keys are able to access ERC20 and ERC721 token contracts amongst others, transferring all tokens from the account out andonfigure the permissions on external modules on session keys. They would be able to remove all restrictions set on themselves this way, or rotate the keys of other keys with higher privileges into keys that they control. Commit 5e6f540d249afcaeaf76ab95517d0359fde883b0 fixes this issue.

Affected Software

1 affected component
Alchemy Modular Account<2.x

Event History

May 15, 2025
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-46834?

CVE-2025-46834 is classified as a high severity vulnerability affecting the Alchemy Modular Account.

2

How do I fix CVE-2025-46834?

To fix CVE-2025-46834, users should update to version 2.x after commit 5e6f540d249afcaeaf76ab95517d0359fde883b0.

3

What type of vulnerability is CVE-2025-46834?

CVE-2025-46834 involves insecure handling of session keys in the Alchemy Modular Account.

4

Who is affected by CVE-2025-46834?

Owners of Alchemy Modular Accounts using versions prior to the specified commit are affected by CVE-2025-46834.

5

What are the potential impacts of CVE-2025-46834?

CVE-2025-46834 may allow unauthorized access or manipulation of user accounts due to improper session key management.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203