Impact
The flaw lies in ZenHive mpp’s handling of the aa_authorization_list within the fee payer policy. The system counts every delegation in the list as intrinsic gas without validating the specified quantity. An attacker can attach a large number of delegations to a single sponsored payment, causing the sponsor to pay a dramatically inflated gas cost and potentially delegate code or upgrade accounts at the sponsor’s expense. This is a manifestation of improper input validation (CWE‑1284).
Affected Systems
The vulnerability exists in ZenHive mpp versions from 0.2.0 up through 0.16.1. Systems running any of these versions with Tempo fee‑payer sponsorship enabled are affected.
Risk and Exploitability
The flaw carries a CVSS score of 8.3, indicating high severity, while the EPSS score is currently unavailable and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can exploit the issue remotely by sending a crafted fee‑payer transaction; the attack does not require credentials beyond the ability to submit an envelope. The impact includes significant financial loss through gas cost inflation and unauthorized delegation of account control. Given the lack of a publicly disclosed exploit and the need for a sponsor‑enabled configuration, the exploitation likelihood is moderate but not negligible.
OpenCVE Enrichment