Vulnerability Description
An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows attackers to deploy a contract without capability enforcement, and execute unauthorized actions on the blockchain.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cosmwasm | Cosmwasm | < 2.2.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/H3T76/8096a6ff9410f3a6d9a25db1a68ae657#file-cve-2025-255Broken Link
- https://gist.github.com/H3T76/8096a6ff9410f3a6d9a25db1a68ae657#file-cve-2025-255Broken Link
FAQ
What is CVE-2025-25500?
CVE-2025-25500 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows attackers to deploy a contract...
How severe is CVE-2025-25500?
CVE-2025-25500 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-25500?
Check the references section above for vendor advisories and patch information. Affected products include: Cosmwasm Cosmwasm.