NONE · 0

CVE-2025-53638

Solady is software that provides Solidity snippets with APIs. Starting in version 0.0.125 and prior to version 0.1.24, when an account is deployed via a proxy, using regular Solidity to call its initi...

Vulnerability Description

Solady is software that provides Solidity snippets with APIs. Starting in version 0.0.125 and prior to version 0.1.24, when an account is deployed via a proxy, using regular Solidity to call its initialization function may result in a silent failure, if the initialization function does not return a `bool` or some other return data. This is because regular Solidity uses `extcodesize(proxy)` to decide if call succeeds. This is insufficient in the case when the proxy points to an empty implementation. Users should upgrade to Solady v0.1.24 or later to receive a patch. Deploy any affected implementations and their factories on new EVM chains as soon as possible.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-53638?

CVE-2025-53638 is a documented vulnerability. Solady is software that provides Solidity snippets with APIs. Starting in version 0.0.125 and prior to version 0.1.24, when an account is deployed via a proxy, using regular Solidity to call its initi...

How severe is CVE-2025-53638?

CVSS scoring is not yet available for CVE-2025-53638. Check NVD for updates.

Is there a patch for CVE-2025-53638?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.