CVE-2025-46834: Alchemy's Modular Account can use executeUserOp to bypass allowlist prevalidation hook
Alchemy's Modular Account is a smart contract account that is compatible with ERC-4337 and ERC-6900. In versions on the 2.x branch prior to commit 5e6f540d249afcaeaf76ab95517d0359fde883b0, owners of Modular Accounts can grant session keys (scoped external keys) to external parties and would use the allowlist module to restrict which external contracts can be accessed by the session key. There is a bug in the allowlist module in that we don't check for the executeUserOp -> execute or executeBatch path, effectively allowing any session key to bypass any access control restrictions set on the session key. Session keys are able to access ERC20 and ERC721 token contracts amongst others, transferring all tokens from the account out andonfigure the permissions on external modules on session keys. They would be able to remove all restrictions set on themselves this way, or rotate the keys of other keys with higher privileges into keys that they control. Commit 5e6f540d249afcaeaf76ab95517d0359fde883b0 fixes this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46834?
CVE-2025-46834 is classified as a high severity vulnerability affecting the Alchemy Modular Account.
How do I fix CVE-2025-46834?
To fix CVE-2025-46834, users should update to version 2.x after commit 5e6f540d249afcaeaf76ab95517d0359fde883b0.
What type of vulnerability is CVE-2025-46834?
CVE-2025-46834 involves insecure handling of session keys in the Alchemy Modular Account.
Who is affected by CVE-2025-46834?
Owners of Alchemy Modular Accounts using versions prior to the specified commit are affected by CVE-2025-46834.
What are the potential impacts of CVE-2025-46834?
CVE-2025-46834 may allow unauthorized access or manipulation of user accounts due to improper session key management.