Junglewise Threat Intelligence

CVE-2023-30543: Uniswap web3-react stale chainId in connection flow

CVE-2023-30543 · Severity: low · CVSS 3.1 · Published 2023-04-18

Vendors: npm.

Executive brief

web3-react is a popular library that enables Web3 applications to connect to blockchain wallets like MetaMask. If a user switches blockchain networks during connection setup, the library may report an outdated chain ID to the application. This could cause financial transaction errors—for example, a token-swapping app might send user funds to the wrong blockchain address based on incorrect chain information.

Technical details

The vulnerability is a race condition (CWE-362) in the chainId state management of web3-react's wallet connector modules. When a user changes chains during the connection flow, the useWeb3React() hook may return a stale chainId value that does not reflect the current network selection. The issue affects the Coinbase Wallet, EIP-1193, MetaMask, and WalletConnect connectors. An attacker with high privileges and user interaction (e.g., by tricking a user into switching chains mid-connection) can cause the application to derive incorrect contract addresses or data from the outdated chain ID. The vulnerability has been patched in specified beta versions of the affected connector packages (PR #749).

Affected products

  • Uniswap web3-react 6.0.0 to <8.0.35-beta.0 (coinbase-wallet); 6.0.0 to <8.0.27-beta.0 (eip1193); 6.0.0 to <8.0.30-beta.0 (metamask); 6.0.0 to <8.0.37-beta.0 (walletconnect)

Timeline

  • 2023-04-17: disclosed
  • 2023-04-18: patched: Fixes released in web3-react @8.0.35-beta.0 (coinbase-wallet), @8.0.27-beta.0 (eip1193), @8.0.30-beta.0 (metamask), @8.0.37-beta.0 (walletconnect)

References