LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight. This vulnerability can lead to a total loss of funds for the node backend. This vulnerability is fixed in 0.12.6.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-1900 LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight. This vulnerability can lead to a total loss of funds for the node backend. This vulnerability is fixed in 0.12.6.
Github GHSA Github GHSA GHSA-3j4h-h3fp-vwww LNbits improperly handles potential network and payment failures when using Eclair backend
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T02:59:21.774Z

Reserved: 2024-05-07T13:53:00.131Z

Link: CVE-2024-34694

cve-icon Vulnrichment

Updated: 2024-08-02T02:59:21.774Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-14T15:15:50.637

Modified: 2024-11-21T09:19:12.763

Link: CVE-2024-34694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:16:10Z